CVE-2026-11834
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
22/06/2026
Last modified:
26/06/2026
Description
A command<br />
injection vulnerability has been identified in the DHCP option processing logic<br />
in multiple TP-Link router models, due to insufficient validation of externally<br />
supplied DHCP option data. An adjacent attacker may exploit this<br />
vulnerability by supplying crafted DHCP responses, potentially resulting in unauthorized<br />
command execution during device initialization or provisioning workflows. This<br />
typically occurs when the device is in a factory-default or unconfigured state.<br />
<br />
<br />
<br />
<br />
<br />
Successful<br />
exploitation may allow an adjacent, unauthenticated attacker to execute<br />
arbitrary commands with elevated privileges, potentially leading to full<br />
compromise of the affected device and unauthorized administrative control.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
References to Advisories, Solutions, and Tools
- https://mattg.systems/posts/cve-2026-11834/
- https://www.tp-link.com/en/support/download/archer-c20/
- https://www.tp-link.com/en/support/download/archer-mr200/#Firmware
- https://www.tp-link.com/en/support/download/archer-mr402/#Firmware
- https://www.tp-link.com/en/support/download/archer-vr2100/#Firmware
- https://www.tp-link.com/en/support/download/tl-mr6400/v7/#Firmware
- https://www.tp-link.com/us/support/download/archer-c20/
- https://www.tp-link.com/us/support/faq/5141/



