yousukezan[verified]@yousukezanPatch
TP‑Link released patches for three severe command‑injection CVEs affecting Archer routers, detailing the vulnerabilities and fix builds, but reports confirm no active exploitation has been observed.
kokumօtօ[verified]@__kokumotoDisclosure
The post announces a CP-2026-9254 unauthenticated OS command injection flaw in TP‑Link routers, notes that it allows root‑level command execution from LAN through a parental‑control defect, and indicates that a patch has been released.
Rıdvan Yağlı[verified]@ridvanyagliPatch
TP‑Link disclosed a critical command‑injection flaw (CVE‑2026‑9254) that lets unauthenticated local attackers run OS commands with root privileges, and has issued firmware updates that users should install.
CVE@CVEnewDisclosure
The snippet announces CVE-2026-9254 as an unauthenticated OS command injection flaw affecting Archer BE800 V1, BE3600 V1, and AX75 V1 routers, citing improper filtering. No exploit code, PoC, or evidence of active exploitation is provided.
ケイ | IT・セキュリティ系副業Webライター@Teeeda_workerDisclosure
The text announces CVE‑2026‑9254, a high‑severity vulnerability in TP‑Link Archer routers that allows root command execution from the LAN.
Kyssta@kysstalolPatch
CVE-2026-9254 is an unauthenticated OS command injection affecting TP‑Link routers; firmware updates are now available to fix the vulnerability.
Kyssta@kysstalolPatch
A newly disclosed unauthenticated OS command injection (CVE‑2026‑9254, CVSS 8.7) affects TP‑Link routers, and firmware updates have been released to remediate the issue.
Daily CyberSecurity@Daily_CyberSecPatch
TP‑Link has released patches for multiple OS command injection vulnerabilities, including CVE‑2026‑9254, with no indication of active exploitation or a Proof of Concept.