CVE-2026-9030
Severity CVSS v4.0:
MEDIUM
Type:
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
07/08/2026
Last modified:
18/08/2026
Description
A denial-of-service<br />
vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool<br />
instruction handlng path in httpd does not properly synchronize or safely manage<br />
concurrent systool operations. <br />
<br />
<br />
<br />
<br />
<br />
By sending<br />
crafted systool instructions through the asynchronous request path, successful<br />
exploitation may cause the httpd process or device management service to crash<br />
and may result in temporary loss of access to the web management interface or<br />
device reboot.
Impact
Base Score 4.0
6.80
Severity 4.0
MEDIUM


