CVE-2026-9031: TP-Link Systems Inc Archer a6 v4

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic. Successful exploitation may cause httpd process or device to crash, resulting in loss of access to the web interface and a denial-of-service condition.

Affected products

Published 2026-08-07. Last modified 2026-08-18.