An input validation
vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation
of user-supplied data before it is processed by internal flash-write handling
logic.









Successful
exploitation may cause httpd process or device to crash, resulting in loss of access
to the web interface and a denial-of-service condition.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 08 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link archer A6 V4
Vendors & Products Tp-link
Tp-link archer A6 V4

Fri, 07 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic. Successful exploitation may cause httpd process or device to crash, resulting in loss of access to the web interface and a denial-of-service condition.
Title Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-10T18:23:52.453Z

Reserved: 2026-05-19T16:30:34.816Z

Link: CVE-2026-9031

cve-icon Vulnrichment

Updated: 2026-08-10T17:28:23.875Z

cve-icon NVD

Status : Received

Published: 2026-08-07T21:17:30.530

Modified: 2026-08-10T19:17:36.603

Link: CVE-2026-9031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:40:18Z

Weaknesses