MEDIUM 6.8 NVD
CVE-2026-9030
A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not properly syn
A denial-of-service
vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool
instruction handlng path in httpd does not properly synchronize or safely manage
concurrent systool operations.
By sending
crafted systool instructions through the asynchronous request path, successful
exploitation may cause the httpd process or device management service to crash
and may result in temporary loss of access to the web management interface or
device reboot.
References
- https://www.tp-link.com/en/support/download/archer-a6/v4/#Firmware
- https://www.tp-link.com/en/support/faq/5234/
- https://www.tp-link.com/us/support/download/archer-a6/v4/#Firmware
This medium severity vulnerability with a CVSS score of 6.8 was published on 2026-08-07 via NVD.
vulnfeed aggregates 9044 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.