
TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers. #TPLink #CyberSecurity #CVE20269254 #CommandInjection https://securityonline.info/cve-2026-9254-unauthenticated-os-command-injection/
Post summary
TP‑Link has released a patch for CVE‑2026‑9254, an unauthenticated OS command injection vulnerability, while also noting other risks such as CVE‑2026‑16348 and CVE‑2026‑78541.


