securityonline.info 8/25/2026, 3:01:15 AM · external

CVE-2026-9254: Unauthenticated OS Command Injection Hits TP-Link Archer

CVE-2026-9254: Unauthenticated OS Command Injection Hits TP-Link Archer
CyberSIXT Evidence Panel
Primary Source tp-link.com
CISA KEV Not in KEV
Patch Patch Available

A critical alert highlights the discovery of multiple vulnerabilities affecting TP-Link Archer routers. The most severe is CVE-2026-9254, an unauthenticated OS command injection flaw that allows attackers to gain root access and potentially compromise connected networks. Other vulnerabilities include CVE-2026-16348, which enables command injection via VPN connections by authenticated users, and CVE-2026-78541, which involves stored command injection.

TP-Link has released patches for affected devices, and users are urged to update their firmware immediately to mitigate risks. The vulnerabilities could enable attackers to execute arbitrary commands, impacting device integrity and network security. No current exploitation has been confirmed in the wild.

View Primary Source Via securityonline.info

Article by CyberSIXT