Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-9030

Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-362 Ejecución concurrente utilizando recursos compartidos con una incorrecta sincronización (Condición de carrera)
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026

Descripción

*** Pendiente de traducción *** A denial-of-service<br /> vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool<br /> instruction handlng path in httpd does not properly synchronize or safely manage<br /> concurrent systool operations.  <br /> <br /> <br /> <br /> <br /> <br /> By sending<br /> crafted systool instructions through the asynchronous request path, successful<br /> exploitation may cause the httpd process or device management service to crash<br /> and may result in temporary loss of access to the web management interface or<br /> device reboot.