Click to skip the navigation bar

Security Advisory: Multiple Vulnerabilities in Archer A6 (CVE-2026-9030 & CVE-2026-9031)

Security Advisory
Last updated: August 7, 2026

Security Advisory: Multiple Vulnerabilities in Archer A6 (CVE-2026-9030 & CVE-2026-9031)

Description of Vulnerabilities and Impacts:

Multiple vulnerabilities have been identified in Archer A6 v4.

CVE-2026-9030 Authenticated Denial-of-Service in HTTPD Asynchronous systool Handler

A denial-of-service vulnerability exists in httpd service where the asynchronous systool instruction handlng path in httpd does not properly synchronize or safely manage concurrent systool operations.

By sending crafted systool instructions through the asynchronous request path, successful exploitation may cause the httpd process or device management service to crash and may result in temporary loss of access to the web management interface or device reboot.

CVE-2026-9031 Authenticated Unvalidated Flash Write in HTTP_WRITEOEM Handler

An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic.

Successful exploitation may cause httpd process or device to crash, resulting in loss of access to the web interface and a denial-of-service condition.

Both CVE-2026-9030 and CVE-2026-9031 share the same CVSS scores:

CVSS v4.0 Score: 6.8/ Medium

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products/Versions and Fixes:

Affected Product

Hardware Version

Fixed Version

Archer A6

V4

V4_1.15.10 Build 260625 Rel.25447

Recommendations:

We strongly recommend that users with affected devices take the following actions:

  1. Follow the instructions to update to the latest firmware version to fix the vulnerabilities:

US: Download for Archer A6 | TP-Link

EN: Download for Archer A6 | TP-Link

Disclaimer:

This advisory is provided for informational purposes only and is subject to change without notice. The information is provided “as is” without warranties of any kind. TP-Link recommends that customers promptly apply available firmware updates or implement documented workarounds as provided in this advisory. Devices/systems that are not updated or mitigated as described may remain vulnerable, and TP-Link disclaims any responsibility or liability for any damages or losses arising from a failure to implement such updates.

Related FAQs

Looking for More

Is this faq useful?

Your feedback helps improve this site.

Community

TP-Link Community

Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.

Visit the Community >