CVE-2026-9044Disclosure(tp-link / archer_axe75)

LOWCVSS 8.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tp-link archer_axe75 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters.  Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • archer_axe75
  • archer_axe75_firmware

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 4 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 7 mentions (2026-08-01); latest day: 1
  • 10 total mentions across 4 days

Affected systems

Vendors
Products
archer_axe75archer_axe75_firmware

1 version affected across 2 products

Deep dive

Activity timeline10 mentions / 4d
02457Mentions · 2026-08-01: 7Mentions · 2026-08-02: 1Mentions · 2026-08-05: 1Mentions · 2026-08-06: 1Patch / Workaround · 2026-08-01: 2Patch / Workaround · 2026-08-02: 1Patch / Workaround · 2026-08-05: 1Technical Details · 2026-08-01: 6Technical Details · 2026-08-05: 1Technical Details · 2026-08-06: 108-0108-0208-0508-06
Signal classification3 categories
Disclosure
440.0%
Patch
440.0%
General
220.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-08-017
Disclosure3General2Patch2
2026-08-021
Patch1
2026-08-051
Patch1
2026-08-061
Disclosure1
Full discourse10 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    CVE-2026-9044 is a command injection flaw in TP-Link Archer AXE75 OpenVPN, CVSS 8.5. Update to firmware 1.5.6 Build 20260623 now. #TPLink #CVE20269044 #CommandInjection #OpenVPN #RouterSecurity #CyberSecurity http://securityonline.info/cve-2026-9044-tp-link-archer-axe75-command-injection/

    Post summary

    CVE-2026-9044 is a command injection vulnerability in TP‑Link Archer AXE75 OpenVPN with a CVSS score of 8.5. Updating to firmware 1.5.6 Build 20260623 mitigates the issue.

    00010445
    12.6K followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-9044: TP-LinkのコマンドインジェクションがArcher AXE75に影響を及ぼす CVE-2026-9044: TP-Link Command Injection Hits Archer AXE75 #DailyCyberSecurity (Aug 5) https://securityonline.info/cve-2026-9044-tp-link-archer-axe75-command-injection/

    Post summary

    A new CVE-2026-9044 command-injection vulnerability affecting TP-Link Archer AXE75 routers has been disclosed.

    00000328
    4.9K followersView on X
  • SecureShield@SecureShield_
    Patch

    一次情報(NVD): https://nvd.nist.gov/vuln/detail/CVE-2026-9044 参照元(ベンダー等): https://www.tp-link.com/en/support/download/archer-axe75/v1/#Firmware, https://www.tp-link.com/us/support/download/archer-axe75/v1/#Firmware

    Post summary

    The post cites CVE-2026-9044 and provides links to TP‑Link firmware downloads, indicating that a patch is available, but does not mention PoC, exploitation, or technical details.

    0000054
    25 followersView on X
  • VulDB 🛡@vuldb
    General

    We have just added an important vulnerability affecting TP-Link AXE75 (CVE-2026-9044) https://vuldb.com/vuln/385160

    Post summary

    A new CVE (CVE-2026-9044) affecting the TP‑Link AXE75 router has been announced, with a reference to a VULDB entry for further information.

    00000131
    2.3K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    TP-Link AXE75 V1 routers have a CVSS 8.5 command injection issue in the VPN module (CVE-2026-9044). Organizations using these devices should review firmware and limit VPN exposure. https://nvd.nist.gov/vuln/deta… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/tNziWD2Tpq

    Post summary

    TP‑Link AXE75 V1 routers suffer from CVE‑2026‑9044, a command injection flaw (CVSS 8.5). Users are advised to update firmware and restrict VPN use.

    0000056
    90 followersView on X
  • TECHEPAGES@techepages
    Patch

    ⚠️ TP-Link Archer AXE75 (HW v1) has an OpenVPN command injection flaw (CVE-2026-9044, CVSS 8.5) — an authenticated attacker on your local network could import a rigged VPN config file and gain full control of the router. ✅ Fix: update to firmware 1.5.6 Build 20260623 now.

    Post summary

    The text announces a critical OpenVPN command injection vulnerability in TP‑Link Archer AXE75 and directs users to a specific firmware update that resolves the issue.

    0000054
    36 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-9044 An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arb… https://www.cve.org/CVERecord?id=CVE-2026-9044 ----- Traducción: CVE-2026-9044 Exi… http://infoflow.cloud`

    Post summary

    A newly disclosed OS command injection vulnerability (CVE‑2026‑9044) has been identified in the VPN module of TP‑Link AXE75 V1 routers, permitting an authenticated adjacent attacker to run arbitrary commands.

    0000050
    96 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-9044 An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arb… https://www.cve.org/CVERecord?id=CVE-2026-9044

    Post summary

    The post announces an OS command injection flaw in TP‑Link AXE75 V1 routers, providing technical details but no PoC, exploit code, active exploitation data, or patch information.

    00000813
    57.9K followersView on X
  • SecNews@SecNews_GR
    General

    TP-Link Archer AXE75: ευπάθεια εντολών στο OpenVPN (CVE-2026-9044) https://secn.ws/4t5Aog

    Post summary

    The post references CVE‑2026‑9044, describing it as a command vulnerability in TP‑Link Archer AXE75’s OpenVPN, but offers no proof‑of‑concept, exploit code, patch, or evidence of active exploitation.

    00000143
    7.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-9044 OS Command Injection in TP-Link AXE75 V1 Router VPN Module https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9044

    Post summary

    The text announces a newly reported OS Command Injection vulnerability (CVE-2026-9044) affecting the TP-Link AXE75 V1 Router VPN Module, but provides no further exploitation or remediation details.

    00000121
    4.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linkarcher_axe751.0--
OStp-linkarcher_axe75_firmware---

Explore more