CVE-2026-22228: TP-Link Archer BE230 Firmware
Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.
An authenticated user with high privileges may trigger a denial‑of‑service condition in TP-Link Archer BE230 v1.2 by restoring a crafted configuration file containing an excessively long parameter. Restoring such a file can cause the device to become unresponsive, requiring a reboot to restore normal operation. This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420.
Affected products
- TP-Link Archer BE230 Firmware: before 1.2.4 (fixed in 1.2.4)
Published 2026-02-03. Last modified 2026-06-17.