CVE-2026-9044

TP-Link · AXE75 V1

TP-Link AXE75 V1 routers are susceptible to OS command injection in the VPN module, enabling remote code execution by high-privileged users.

Executive summary

A high-severity OS command injection vulnerability in the VPN module of TP-Link AXE75 V1 routers enables attackers with high privileges to execute arbitrary commands.

Vulnerability

This is an OS command injection vulnerability (CWE-78) located within the VPN module. It requires high-privileged (administrator) access to successfully exploit, allowing the execution of arbitrary system commands.

Business impact

With a CVSS score of 8.5, this vulnerability represents a significant risk to network infrastructure. If exploited, an attacker could gain full control over the router, potentially leading to complete network compromise, interception of traffic, or the deployment of persistent threats within the local network.

Remediation

Immediate Action: Update the router firmware to version 1.5.6 Build 20260623 or later.

Proactive Monitoring: Monitor the router logs for signs of unauthorized configuration changes or unusual outbound traffic patterns indicative of command injection.

Compensating Controls: Restrict administrative access to the router interface to trusted IP addresses only and disable remote management features if they are not required.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Network administrators must ensure that all TP-Link AXE75 V1 devices are updated immediately. Given that command injection can lead to full system compromise, patching is the only effective way to mitigate this risk.