Command Injection Vulnerability in TP-Link Archer AX90 Router
CVE-2026-84682
7.7HIGH
What is CVE-2026-84682?
A command injection vulnerability has been identified in the TDDPv2 service of the TP-Link Archer AX90 router, specifically in the handling of the setProductVer command. This security flaw allows unauthenticated attackers on adjacent networks to execute arbitrary commands with root privileges during the device boot process. If exploited, this vulnerability could lead to complete compromise of the device, enabling unauthorized access and control. It is crucial for users to apply any available patches to mitigate this risk and safeguard their network security.
Affected Version(s)
Archer AX90 v1 0 < 1.1.4 Build 20260927
