PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9151 TP-Link Systems Inc. CVE debrief

An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1, AX18 v1, and AX1300 v1.6 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue stems from improper filtering of special characters. Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability.

Vendor
TP-Link Systems Inc.
Product
Archer AX12 V1
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-10
Original CVE updated
2026-06-10
Advisory published
2026-06-10
Advisory updated
2026-06-10

Who should care

Administrators and users of TP-Link Archer AX12, AX17, AX18, and AX1300 routers should be aware of this vulnerability and take necessary actions to mitigate the risk.

Technical summary

The vulnerability is caused by improper filtering of special characters in the VPN module of the affected routers. An adjacent, authenticated attacker can exploit this vulnerability by importing a specially crafted VPN client configuration file, allowing them to execute arbitrary commands on the device.

Defensive priority

HIGH

Recommended defensive actions

  • Update the firmware of the affected routers to the latest version.
  • Restrict access to the VPN configuration page to only trusted users.
  • Monitor the router's logs for suspicious activity.

Evidence notes

The CVE record and NVD detail pages provide information on the vulnerability, including its CVSS score and weaknesses.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9151 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9151

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9151 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9151

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.tp-link.com/en/support/download/archer-ax12/

    f23511db-6c3e-4e32-a477-6aa17d310630

  • Source reference

    Unverified legacy reference

    URL: https://www.tp-link.com/en/support/download/archer-ax17/

    f23511db-6c3e-4e32-a477-6aa17d310630

  • Source reference

    Unverified legacy reference

    URL: https://www.tp-link.com/en/support/download/archer-ax18/

    f23511db-6c3e-4e32-a477-6aa17d310630

  • Source reference

    Unverified legacy reference

    URL: https://www.tp-link.com/us/support/download/archer-ax1300/

    f23511db-6c3e-4e32-a477-6aa17d310630

  • Source reference

    Unverified legacy reference

    URL: https://www.tp-link.com/us/support/faq/5125/

    f23511db-6c3e-4e32-a477-6aa17d310630

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.