OS Command Injection Vulnerability in TP-Link Archer C20 Web Management Interface
CVE-2026-75616

8.5HIGH

Key Information:

Vendor
CVE Published:
19 August 2026

What is CVE-2026-75616?

An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when handling specific WAN-related configuration operations. An authenticated administrator can exploit this issue due to inadequate input validation, enabling them to execute arbitrary system commands with elevated privileges. This could result in a complete compromise of the device, thus jeopardizing the confidentiality, integrity, and availability of not only the device itself but also the network traffic traversing through it. It is essential for users to apply available patches and updates to mitigate this risk.

Affected Version(s)

Archer C20 v6 Linux 0

Archer C20 v6 Linux 0

Archer C20 v6 Linux 0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniil Gordeev (totekuh)
.