CVE-2026-9151
An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1
Published: 2026-06-10 · Last updated: 2026-06-10
Severity and scoring
- CWE
- CWE-78
Description
An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v1.6 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue stems from improper filtering of special characters. Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-9151
- [Other]https://www.tp-link.com/en/support/download/archer-ax12/#Firmware
- [Other]https://www.tp-link.com/en/support/download/archer-ax17/#Firmware
- [Other]https://www.tp-link.com/en/support/download/archer-ax18/#Firmware
- [Other]https://www.tp-link.com/us/support/download/archer-ax1300/#Firmware
- [Other]https://www.tp-link.com/us/support/faq/5125/
Related CVEs
Same CWE
- CVE-2026-49219 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.5 MEDIUM)
- CVE-2026-42563 — Dulwich is a pure-Python implementation of the Git file formats and protocols
- CVE-2026-0273 — A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrict...
- CVE-2026-6893 — A flaw was found in dracut (8.8 HIGH)
- CVE-2026-46643 — Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page