THE content highlights a critical command injection vulnerability (CVE-2026-9044) in TP-Link's Archer AXE75 V1 router, specifically in its OpenVPN module. The vulnerability, which has a high CVSS score of 8.5, allows an authenticated attacker on the same network to gain full control of the device by exploiting improper character filtering. TP-Link has issued a patch in firmware version 1.5.6 Build 20260623, and users are advised to update immediately as there are no workarounds available. Currently, there have been no confirmed exploitations in the wild.
CVE-2026-9044: TP-Link Command Injection Hits Archer AXE75
CyberSIXT Evidence Panel
Article by CyberSIXT