CVE-2026-9044: Command Injection Vulnerability in OpenVPN of TP-Link Archer AXE75
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters.
Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9044?
CVE-2026-9044 has a risk rating of 58, indicating a moderate severity level.
How do I fix CVE-2026-9044?
To mitigate CVE-2026-9044, you should update to the latest firmware provided by TP-Link for the Archer AXE75.
Who is impacted by CVE-2026-9044?
CVE-2026-9044 affects users of the TP-Link Archer AXE75 V1 routers who utilize the VPN module.
What can attackers do with CVE-2026-9044?
An attacker exploiting CVE-2026-9044 can execute arbitrary commands on the TP-Link Archer AXE75 router.
What is the nature of the vulnerability in CVE-2026-9044?
CVE-2026-9044 is an OS command injection vulnerability that arises from improper filtering in the VPN module.