Junglewise Threat Intelligence

CVE-2026-9151: TP-Link Archer Routers OS command injection in VPN module

CVE-2026-9151 · Severity: info · CVSS 8.5 · Published 2026-06-10

Vendors: TP-Link.

Executive brief

TP-Link Archer routers are consumer-grade networking devices used to provide internet connectivity and secure VPN access. A security flaw in the VPN module allows an authorized user on the local network to take complete control of the router by uploading a malicious configuration file. This could lead to the interception of network traffic, service outages, or unauthorized access to other devices on the home or office network.

Technical details

An OS command injection vulnerability (CWE-78) exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1, AX18 v1, and AX1300 v1.6 routers. The flaw is caused by improper filtering of special characters when processing VPN client configuration files. An authenticated attacker located on the adjacent network can exploit this by importing a specially crafted configuration file to execute arbitrary system commands. Successful exploitation grants the attacker full control over the device. TP-Link has released firmware updates (e.g., version 1.5.0 Build 20260605 for AX12/AX17) to address this issue.

Affected products

  • TP-Link Archer AX12 v1
  • TP-Link Archer AX17 v1
  • TP-Link Archer AX18 v1
  • TP-Link Archer AX1300 v1.6

Timeline

  • 2026-06-09: patched: Firmware version 1.5.0 Build 20260605 released for affected models
  • 2026-06-10: disclosed: CVE-2026-9151 published

References

Related threats