CVE-2026-9031: Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6

Published Aug 7, 2026
·
Updated

An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic.

Successful exploitation may cause httpd process or device to crash, resulting in loss of access to the web interface and a denial-of-service condition.

Affected Software

1 affected component
HTTPD Service=

Event History

Aug 7, 2026
CVE Published
via MITRE·08:40 PM
Data Sourced
via MITRE·08:40 PM
DescriptionWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9031?

CVE-2026-9031 has a risk rating of 23, indicating a significant vulnerability that could lead to a Denial-of-Service.

2

How do I fix CVE-2026-9031?

To address CVE-2026-9031, it is recommended to update the TP-Link Archer A6 firmware to the latest version that resolves this vulnerability.

3

What impact does CVE-2026-9031 have on my device?

Exploitation of CVE-2026-9031 can cause the httpd process or the device itself to crash, resulting in a loss of access to the web interface.

4

Is CVE-2026-9031 a hardware or software vulnerability?

CVE-2026-9031 is a software vulnerability found specifically in the HTTPD Service of the TP-Link Archer A6.

5

What type of vulnerability is CVE-2026-9031 classified as?

CVE-2026-9031 is classified as an Input Validation vulnerability due to insufficient validation of user-supplied data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203