MEDIUM
Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6
Published Aug 7, 2026
6.8
MEDIUMCVSS 4.0
EPSS 0.26%
Description
An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic.
Successful exploitation may cause httpd process or device to crash, resulting in loss of access to the web interface and a denial-of-service condition.
Affected products
-
- Version 0StatusaffectedConstraints<V4_1.15.10 Build 260625 Rel.25447
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| TP-Link Systems Inc. | Archer A6 v4 | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://www.tp-link.com/en/support/download/archer-a6/v4/#Firmware patch
- https://www.tp-link.com/en/support/faq/5234/ vendor-advisory
- https://www.tp-link.com/us/support/download/archer-a6/v4/#Firmware patch
| Link | Providers | Tags |
|---|---|---|
| https://www.tp-link.com/en/support/download/archer-a6/v4/#Firmware | patch | |
| https://www.tp-link.com/en/support/faq/5234/ | vendor-advisory | |
| https://www.tp-link.com/us/support/download/archer-a6/v4/#Firmware | patch |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TPLink
Published Aug 7, 2026
Updated Aug 10, 2026
Reserved May 19, 2026
Link CVE-2026-9031
CISA Vulnrichment
Updated Aug 10, 2026