securityonline.info 8/5/2026, 3:51:38 PM · external

CVE-2026-9044: TP-Link Command Injection Hits Archer AXE75

CVE-2026-9044: TP-Link Command Injection Hits Archer AXE75
CyberSIXT Evidence Panel
Primary Source tp-link.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

THE content highlights a critical command injection vulnerability (CVE-2026-9044) in TP-Link's Archer AXE75 V1 router, specifically in its OpenVPN module. The vulnerability, which has a high CVSS score of 8.5, allows an authenticated attacker on the same network to gain full control of the device by exploiting improper character filtering. TP-Link has issued a patch in firmware version 1.5.6 Build 20260623, and users are advised to update immediately as there are no workarounds available. Currently, there have been no confirmed exploitations in the wild.

View Primary Source Via securityonline.info

Article by CyberSIXT