← Back to CVE List
CVE-2026-9044NVD
Vulnerability Summary
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters.
Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability.
Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability.
CVSS v4.0 Base Metrics — Score 8.5 (HIGH)
Attack VectorAdjacent
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredHigh
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)Low
Integrity (Subsequent System)Low
Availability (Subsequent System)Low
Affected & Patched Versions
- TP-Link Systems Inc. AXE75 V1 < 1.5.6 Build 20260623
- TP-Link Systems Inc. AXE75 V1 1.5.6 Build 20260623