CVE-2026-9151
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
10/06/2026
Last modified:
10/06/2026
Description
An OS<br />
command injection vulnerability exists in the VPN module of TP-Link Archer AX12<br />
v1, AX17 v1. AX18 v1, and AX1300 v1.6 routers. This vulnerability allows an<br />
adjacent, authenticated attacker to execute arbitrary commands on the device by<br />
importing a specially crafted VPN client configuration file. The issue stems<br />
from improper filtering of special characters. <br />
<br />
<br />
<br />
<br />
<br />
Successful<br />
exploitation of this vulnerability may enable an attacker to gain full control<br />
of the affected device, potentially compromising configuration integrity,<br />
network security, and service availability.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
References to Advisories, Solutions, and Tools
- https://www.tp-link.com/en/support/download/archer-ax12/#Firmware
- https://www.tp-link.com/en/support/download/archer-ax17/#Firmware
- https://www.tp-link.com/en/support/download/archer-ax18/#Firmware
- https://www.tp-link.com/us/support/download/archer-ax1300/#Firmware
- https://www.tp-link.com/us/support/faq/5125/



