Back

MEDIUM

Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6

Published Aug 7, 2026

Description

An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic.

Successful exploitation may cause httpd process or device to crash, resulting in loss of access to the web interface and a denial-of-service condition.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TPLink
Published Aug 7, 2026
Updated Aug 10, 2026
Reserved May 19, 2026
CISA Vulnrichment
Updated Aug 10, 2026
NVD
Status Awaiting Analysis
Modified Aug 18, 2026
Red Hat
Severity n/a
Public date n/a