OS Command Injection Vulnerability in TP-Link AXE75 V1 Router
CVE-2026-9044
8.5HIGH
What is CVE-2026-9044?
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers, allowing an authenticated adjacent attacker to execute arbitrary commands. By importing a specially crafted VPN client configuration file, attackers can exploit the vulnerability due to improper filtering of special characters. Successful exploitation may give attackers full control over the affected device, compromising configuration integrity, network security, and service availability.
Affected Version(s)
AXE75 V1 0 < 1.5.6 Build 20260623
