TP-LINK has addressed a critical command injection vulnerability in the Archer C20 v6 router, identified as CVE-2026-75616, which has a CVSS score of 8.5. The flaw allows authenticated administrators to execute arbitrary commands, leading to potential full device compromise, although no exploitation has been reported in the wild. Users are advised to update to the patched firmware versions: EU_0.9.1 Build 260811, US_0.9.1 Build 260812, and RU_0.9.1 Build 260812.
The issue could compromise the confidentiality, integrity, and availability of affected devices. To mitigate risks, it's recommended to restrict access to the admin interface and disable unnecessary remote management.