Junglewise Threat Intelligence

CVE-2026-11834: TP-Link Multiple Routers Command Injection in DHCP Option Processing

CVE-2026-11834 · Severity: info · CVSS 8.7 · Published 2026-06-22

Executive brief

A security vulnerability exists in several TP-Link router models used for home and small business internet connectivity. An attacker physically near the device or on the same local network could send malicious data during the router's setup or initialization process. If successful, this allows the attacker to take full control of the router, potentially leading to the theft of data, monitoring of internet traffic, or use of the device for further attacks.

Technical details

A command injection vulnerability (CWE-78) exists in the DHCP option processing logic of multiple TP-Link router models. The flaw stems from insufficient validation of externally supplied DHCP option data during device initialization or provisioning workflows. An unauthenticated attacker located on the adjacent network can exploit this by providing crafted DHCP responses while the device is in a factory-default or unconfigured state. Successful exploitation allows for arbitrary command execution with elevated privileges, potentially leading to full administrative compromise of the device. Firmware updates have been released for affected models to address this issue.

Affected products

  • TP-Link Systems Inc. Archer MR200 v07 < 1.3.0 Build 250605
  • TP-Link Systems Inc. Archer MR200 v8 < 1.5.0 Build 260605
  • TP-Link Systems Inc. Archer MR402 v1 < 1.5.0 Build 260605
  • TP-Link Systems Inc. Archer VR2100 v1 < EU_V1_260330
  • TP-Link Systems Inc. Archer C20 v5 < EU_V5_260317, < US_V5_260419
  • TP-Link Systems Inc. Archer C20 v6 < V6_260608
  • TP-Link Systems Inc. TL-MR6400 v7

Timeline

  • 2026-06-22: disclosed
  • 2026-06-22: advisory

References