TL;DR
TP-Link patched an OS command injection flaw in the Archer C20 v6 router, tracked as CVE-2026-75616. The bug scores 8.5 on CVSS v4.0 and can lead to full device compromise. An authenticated admin can run arbitrary system commands. No exploitation in the wild has been confirmed.
- CVE: CVE-2026-75616
- CVSS: 8.5 (High · CVSSv4)
- Product: TP-Link Systems Inc. Archer C20 v6
- Affected: < EU_0.9.1 Build 260811, < US_0.9.1 Build 260812, < RU_0.9.1 Build 260812
- Impact: Command Injection in Router Web Management Interface
- Status: No confirmed exploitation yet
- Patched in: EU_0.9.1 Build 260811, US_0.9.1 Build 260812, RU_0.9.1 Build 260812
- EPSS: 1.9% (30-day)
- Action: Update to EU_0.9.1 Build 260811, US_0.9.1 Build 260812, RU_0.9.1 Build 260812 now
Why It Matters
The Archer C20 is a widely sold home Wi-Fi router. A router breach exposes every device behind it. This TP-Link Archer C20 command injection flaw threatens that whole network.
TP-Link warns that a successful attack hits the device hard. The advisory says exploitation can harm the “confidentiality, integrity, and availability of the affected device” and its traffic.
How the Attack Works
The flaw sits in the router’s web management interface. It appears when the device handles certain WAN configuration operations. Per TP-Link, an authenticated administrator may exploit “insufficient input validation to execute arbitrary system commands.”
The command injection then runs with elevated privileges. As a result, an attacker gains control of the device itself. TP-Link warns this could result in “full device compromise.” No public proof-of-concept exploit has been reported.
Affected Versions
The bug affects Archer C20 v6 firmware below the fixed builds. The EU model needs 0.9.1 Build 260811 or later. The US and RU models need 0.9.1 Build 260812 or later.
Patch and Mitigation Steps
Update affected routers to the latest fixed firmware right away. TP-Link links the downloads in its official Archer C20 security advisory. Restrict admin interface access to trusted users, and change default credentials. Disable remote management if you do not need it.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!