TL;DR: TP-Link patched a TP-Link command injection flaw in the Archer AXE75 V1 router. Tracked as CVE-2026-9044, it carries a CVSS v4.0 score of 8.5. Firmware 1.5.6 Build 20260623 fixes the issue.
- CVE: CVE-2026-9044
- CVSS: 8.5 (High · CVSSv4)
- Product: TP-Link Systems Inc. AXE75 V1
- Affected: < 1.5.6 Build 20260623
- Impact: Command Injection Vulnerability in OpenVPN of TP-Link Archer AXE75
- Status: No confirmed exploitation yet
- Patched in: 1.5.6 Build 20260623
- EPSS: 1.0% (30-day)
- Action: Update to 1.5.6 Build 20260623 now
Why it matters
The flaw lives in the router’s OpenVPN module. TP-Link’s advisory states plainly that “successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device.” That includes configuration integrity, network security, and service availability.
A CVSS v4.0 score of 8.5 places this TP-Link command injection flaw in the High severity range. Full device control means an attacker could rewrite router settings, monitor traffic, or use the device as a foothold into the rest of the network.
How the attack works
An attacker on the same network, already authenticated, can import a specially crafted VPN client configuration file. TP-Link’s advisory attributes the TP-Link command injection bug to improper filtering of special characters during that import process.
Because the attacker needs adjacent network access and valid credentials, this is not a remote, unauthenticated flaw. Still, weak or shared router passwords make that bar easier to clear than it sounds.
Exploitation status
No public proof-of-concept or in-the-wild exploitation has been confirmed for CVE-2026-9044 at this time.
Affected versions and patch
Only Archer AXE75 hardware version V1 is affected. TP-Link fixed the flaw in firmware 1.5.6 Build 20260623. Owners should review the official advisory and download the updated firmware right away, since no workaround exists beyond the update.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.