CVE-2026-9030

Severity CVSS v4.0:
MEDIUM
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
07/08/2026
Last modified:
18/08/2026

Description

A denial-of-service<br /> vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool<br /> instruction handlng path in httpd does not properly synchronize or safely manage<br /> concurrent systool operations.  <br /> <br /> <br /> <br /> <br /> <br /> By sending<br /> crafted systool instructions through the asynchronous request path, successful<br /> exploitation may cause the httpd process or device management service to crash<br /> and may result in temporary loss of access to the web management interface or<br /> device reboot.