TP-LINK has issued four security advisories (dated 1 October 2026) detailing seven vulnerabilities across its TP-Link devices, including Tapo C120 and C200 cameras, Archer AX90 routers, Deco M9 Plus, and the TL-WR841N. The most severe entry is CVE-2026-102369, rated 8.7 CVSSv4, which could allow an unauthenticated local attacker to execute commands on Tapo C120 and C200 cameras via a MacTool command injection flaw.
Other flaws include a mix of command injection, a NULL pointer dereference, and information disclosure in the onboarding service. TP-Link notes that none of the flaws have been confirmed as actively exploited, and all affected models have firmware patches available.
Affected versions include Tapo C120 V1 and Tapo C200 V5 (with CVE-2026-102369, CVE-2026-9032, CVE-2026-78577, CVE-2026-78578), Archer AX90 V1 (CVE-2026-84682), Deco M9 Plus V2 (CVE-2026-8618), and TL-WR841N V14 (CVE-2026-102294). The advisories recommend updating to the corresponding patched builds: Tapo C120 V1 to 1.9.4 Build 260813 and Tapo C200 V5 to 1.4.6 Build 260709; Archer AX90 V1 to 1.1.4 Build 20260927; Deco M9 Plus V2 to 1.9.2 Build 20260818; TL-WR841N V14 to 4.19 Build 260821 (EN) or 260820 (US).
Mitigations beyond patching emphasise restricting local network access, for example by using a guest network to limit exposure. The article notes five of the seven flaws require no login, with two capable of full command execution and one enabling root access in some scenarios.