CVE-2026-9031: Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6
An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic.
Successful exploitation may cause httpd process or device to crash, resulting in loss of access to the web interface and a denial-of-service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9031?
CVE-2026-9031 has a risk rating of 23, indicating a significant vulnerability that could lead to a Denial-of-Service.
How do I fix CVE-2026-9031?
To address CVE-2026-9031, it is recommended to update the TP-Link Archer A6 firmware to the latest version that resolves this vulnerability.
What impact does CVE-2026-9031 have on my device?
Exploitation of CVE-2026-9031 can cause the httpd process or the device itself to crash, resulting in a loss of access to the web interface.
Is CVE-2026-9031 a hardware or software vulnerability?
CVE-2026-9031 is a software vulnerability found specifically in the HTTPD Service of the TP-Link Archer A6.
What type of vulnerability is CVE-2026-9031 classified as?
CVE-2026-9031 is classified as an Input Validation vulnerability due to insufficient validation of user-supplied data.