CVE-2026-9031

Summary

An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic.

Successful exploitation may cause httpd process or device to crash, resulting in loss of access to the web interface and a denial-of-service condition.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.Archer A6 v40 < V4_1.15.10 Build 260625 Rel.25447affected

Weaknesses

  • CWE-20: CWE-20 Improper input validation

References