CVE-2026-9031
6.8
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic.
Successful exploitation may cause httpd process or device to crash, resulting in loss of access to the web interface and a denial-of-service condition.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | Archer A6 v4 | 0 < V4_1.15.10 Build 260625 Rel.25447 | affected |
Weaknesses
- CWE-20: CWE-20 Improper input validation
References
- https://www.tp-link.com/us/support/download/archer-a6/v4/#Firmware
- https://www.tp-link.com/en/support/download/archer-a6/v4/#Firmware
- https://www.tp-link.com/en/support/faq/5234/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.