Command Injection Vulnerability in TP-Link Archer AX90 Router
CVE-2026-84682

7.7HIGH

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-84682?

A command injection vulnerability has been identified in the TDDPv2 service of the TP-Link Archer AX90 router, specifically in the handling of the setProductVer command. This security flaw allows unauthenticated attackers on adjacent networks to execute arbitrary commands with root privileges during the device boot process. If exploited, this vulnerability could lead to complete compromise of the device, enabling unauthorized access and control. It is crucial for users to apply any available patches to mitigate this risk and safeguard their network security.

Affected Version(s)

Archer AX90 v1 0 < 1.1.4 Build 20260927

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Can Oztas
.