CVE-2026-84682
7.7
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Summary
A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot.
Successful exploitation may result in complete device compromise through arbitrary command execution with root privileges.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | Archer AX90 v1 | 0 < 1.1.4 Build 20260927 | affected |
Weaknesses
- CWE-78: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://www.tp-link.com/us/support/download/archer-ax90/v1/#Firmware
- https://www.tp-link.com/en/support/download/archer-ax90/v1/#Firmware
- https://www.tp-link.com/us/support/faq/5323/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.