Executive brief
A security vulnerability exists in the TP-Link Archer AXE75 V1 router, a device used to provide high-speed Wi-Fi and network connectivity. An attacker with administrative access to the router's management interface could take complete control of the device by uploading a malicious VPN configuration file. If exploited, this could allow an attacker to intercept network traffic, disable security features, or disrupt internet service for all connected users.
Technical details
An OS command injection vulnerability (CWE-78) exists in the OpenVPN module of TP-Link Archer AXE75 V1 routers. The flaw is caused by improper filtering of special characters within VPN client configuration files during the import process. An adjacent attacker with high privileges (authenticated) can exploit this by uploading a specially crafted configuration file to execute arbitrary system commands. Successful exploitation grants full control over the underlying operating system. TP-Link has released firmware version 1.5.6 Build 20260623 to address this issue.
Affected products
- TP-Link Archer AXE75 V1 Before 1.5.6 Build 20260623
Timeline
- 2026-07-31: advisory: TP-Link published the security advisory and NVD record.
- 2026-06-23: patched: Fixed firmware version 1.5.6 Build 20260623 was released.