NAND Flash Command Execution Issue in TP-Link Archer AX55 by Qualcomm
CVE-2026-80712
What is CVE-2026-80712?
A vulnerability has been identified in the TP-Link Archer AX55's NAND flash handling due to an off-by-one error in the command execution logic. The issue arises from the timing of writing the feature value to the NAND_FLASH_FEATURES register, which occurs after the command execution instead of before. This leads to incorrect values being read and written, rendering the chip unable to operate correctly and causing the device to become unbootable. With the recent enhancements in SPI-NAND OTP support, this vulnerability highlights a significant risk as it can permanently disable the flash memory, leading to data loss and device malfunction. The patch outlined resolves the timing issue, ensuring that feature values are correctly applied during the same transaction as the command execution, restoring the device's functionality.
Affected Version(s)
Linux 7304d1909080ef0c9da703500a97f46c98393fcd < 581e5166f0780103dc91c0d8ebc801f9af4824b0
Linux 7304d1909080ef0c9da703500a97f46c98393fcd < 3ba021079ef2ac6e21e3547328496ac42d22b56a
Linux 7304d1909080ef0c9da703500a97f46c98393fcd < 8fd62901d6bf03f274a49dd0060793cc07dd51b0