All CVEs
Vulnerability intelligence

CVE-2026-9044

TP-Link Systems Inc. AXE75 V1 CWE-78

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters. Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability.

CVSS Score
8.5
High
EPSS — Exploit Probability
1.2%
Riskier than 65% of all CVEs · checked 2026-09-17
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
NVD entry Vendor patch PoC / advisory

1 article across 1 outlet · first covered Aug 5, 2026 · latest Aug 5, 2026

Coverage timeline

Related CVEs — TP-Link Systems Inc.