OS Command Injection Vulnerability in TP-Link Archer C20 Web Management Interface
CVE-2026-75616
Key Information:
- Vendor
Tp-link Systems Inc.
- Status
- Vendor
- CVE Published:
- 19 August 2026
Badges
What is CVE-2026-75616?
An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when handling specific WAN-related configuration operations. An authenticated administrator can exploit this issue due to inadequate input validation, enabling them to execute arbitrary system commands with elevated privileges. This could result in a complete compromise of the device, thus jeopardizing the confidentiality, integrity, and availability of not only the device itself but also the network traffic traversing through it. It is essential for users to apply available patches and updates to mitigate this risk.
Affected Version(s)
Archer C20 v6 Linux 0
Archer C20 v6 Linux 0
Archer C20 v6 Linux 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
