CVE-2026-84682: TP-Link Systems Inc Archer AX90 v1

High severity, CVSS 7.7. EPSS: 1% chance of exploitation in the next 30 days.

A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot.  Successful exploitation may result in complete device compromise through arbitrary command execution with root privileges.

Affected products

  • TP-Link Systems Inc Archer AX90 v1: before 1.1.4 Build 20260927 (fixed in 1.1.4 Build 20260927)

Published 2026-10-01. Last modified 2026-10-02.