A critical alert highlights the discovery of multiple vulnerabilities affecting TP-Link Archer routers. The most severe is CVE-2026-9254, an unauthenticated OS command injection flaw that allows attackers to gain root access and potentially compromise connected networks. Other vulnerabilities include CVE-2026-16348, which enables command injection via VPN connections by authenticated users, and CVE-2026-78541, which involves stored command injection.
TP-Link has released patches for affected devices, and users are urged to update their firmware immediately to mitigate risks. The vulnerabilities could enable attackers to execute arbitrary commands, impacting device integrity and network security. No current exploitation has been confirmed in the wild.