๐Ÿ” CVE Alert

CVE-2026-84682

UNKNOWN 0.0

TDDPv2 setProductVer Command Injection in Archer AX90

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot.ย  Successful exploitation may result in complete device compromise through arbitrary command execution with root privileges.

CWE CWE-78
Vendor tp-link systems inc.
Product archer ax90 v1
Published Oct 1, 2026
Last Updated Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for tp-link systems inc. archer ax90 v1

Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. archer ax90 v1 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TP-Link Systems Inc. / Archer AX90 v1
0 < 1.1.4 Build 20260927

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
tp-link.com: https://www.tp-link.com/us/support/download/archer-ax90/v1/#Firmware tp-link.com: https://www.tp-link.com/en/support/download/archer-ax90/v1/#Firmware tp-link.com: https://www.tp-link.com/us/support/faq/5323/

Credits

Can Oztas