๐Ÿ” CVE Alert

CVE-2026-9030

UNKNOWN 0.0

Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not properly synchronize or safely manage concurrent systool operations.ย  By sending crafted systool instructions through the asynchronous request path, successful exploitation may cause the httpd process or device management service to crash and may result in temporary loss of access to the web management interface or device reboot.

CWE CWE-362
Vendor tp-link systems inc.
Product archer a6 v4
Published Aug 7, 2026
Last Updated Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for tp-link systems inc. archer a6 v4

Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. archer a6 v4 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TP-Link Systems Inc. / Archer A6 v4
0 < V4_1.15.10 Build 260625 Rel.25447

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
tp-link.com: https://www.tp-link.com/us/support/download/archer-a6/v4/#Firmware tp-link.com: https://www.tp-link.com/en/support/download/archer-a6/v4/#Firmware tp-link.com: https://www.tp-link.com/en/support/faq/5234/

Credits

Dariusz Goล„da