Click to skip the navigation bar

Security Advisory on Denial-of-Service Vulnerabilities on Archer BE230 (CVE-2026-22220 & CVE-2026-22228)

Security Advisory
Updated 02-03-2026 17:14:43 PM Number of views for this article116

Description of Vulnerabilities and Impacts:

The following denial-of-service (DoS) vulnerabilities were identified in Archer BE230 v1.2 :

CVE-2026-22220: Improper Input Validation Leading to DoS

A lack of proper input validation in the HTTP processing path may allow a crafted request to cause the device’s web service to become unresponsive, resulting in a denial‑of‑service condition. A network‑adjacent attacker with high privileges could cause the device’s web interface to temporarily stop responding until it recovers or is rebooted.

CVSS v4.0 Score: 6.8 / Medium

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVE-2026-22228: Authenticated DoS via Crafted Configuration Restore

An authenticated user with high privileges may trigger a denial‑of‑service condition by restoring a crafted configuration file containing an excessively long parameter. Restoring such a file can cause the device to become unresponsive, requiring a reboot to restore normal operation.

CVSS v4.0 Score: 6.8 / Medium

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L

Affected Products/Versions and Fixes:

Affected Product Model

Affected Version

Archer BE230 v1.2

< 1.2.4 Build 20251218 rel.70420

Recommendations:

We strongly recommend that users with affected devices take the following actions:

  1. Download and update to the latest firmware version to fix the vulnerabilities.

US: Download for Archer BE230 | TP-Link

EN: Download for Archer BE230 | TP-Link

SG: Download for Archer BE230 | TP-Link Singapore

Acknowledgements:

We thank zeix and 0xakm for reporting these issues to us.

Disclaimer:

If you do not take all recommended actions, this vulnerability will remain. TP-Link cannot bear any responsibility for consequences that could have been avoided by following this advisory.

Looking for More

Is this faq useful?

Your feedback helps improve this site.

Community

TP-Link Community

Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.

Visit the Community >