Security Advisory: Multiple Vulnerabilities in Archer A6 (CVE-2026-9030 & CVE-2026-9031)
Security Advisory: Multiple Vulnerabilities in Archer A6 (CVE-2026-9030 & CVE-2026-9031)
Description of Vulnerabilities and Impacts:
Multiple vulnerabilities have been identified in Archer A6 v4.
CVE-2026-9030 Authenticated Denial-of-Service in HTTPD Asynchronous systool Handler
A denial-of-service vulnerability exists in httpd service where the asynchronous systool instruction handlng path in httpd does not properly synchronize or safely manage concurrent systool operations.
By sending crafted systool instructions through the asynchronous request path, successful exploitation may cause the httpd process or device management service to crash and may result in temporary loss of access to the web management interface or device reboot.
CVE-2026-9031 Authenticated Unvalidated Flash Write in HTTP_WRITEOEM Handler
An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic.
Successful exploitation may cause httpd process or device to crash, resulting in loss of access to the web interface and a denial-of-service condition.
Both CVE-2026-9030 and CVE-2026-9031 share the same CVSS scores:
CVSS v4.0 Score: 6.8/ Medium
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products/Versions and Fixes:
|
Affected Product |
Hardware Version |
Fixed Version |
|
Archer A6 |
V4 |
V4_1.15.10 Build 260625 Rel.25447 |
Recommendations:
We strongly recommend that users with affected devices take the following actions:
- Follow the instructions to update to the latest firmware version to fix the vulnerabilities:
US: Download for Archer A6 | TP-Link
EN: Download for Archer A6 | TP-Link
Disclaimer:
This advisory is provided for informational purposes only and is subject to change without notice. The information is provided “as is” without warranties of any kind. TP-Link recommends that customers promptly apply available firmware updates or implement documented workarounds as provided in this advisory. Devices/systems that are not updated or mitigated as described may remain vulnerable, and TP-Link disclaims any responsibility or liability for any damages or losses arising from a failure to implement such updates.
Looking for More
Is this faq useful?
Your feedback helps improve this site.
TP-Link Community
Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.