Archer C20 v6 固件的 Web 管理接口在处理某些与 WAN 相关的配置操作时存在 OS 命令注入漏洞。经过身份验证的管理员可通过利用输入验证不足的问题,执行任意系统命令,可能导致设备被完全控制。 成功利用该漏洞后,攻击者可以以高权限执行任意命令,从而破坏受影响设备及其流经的网络流量的机密性、完整性和可用性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | Archer C20 v6 | < EU_0.9.1 Build 260811 |
affected |
< US_0.9.1 Build 260812 |
affected | ||
< RU_0.9.1 Build 260812 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | Archer C20 v6 | 0 ~ EU_0.9.1 Build 260811 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75618 | 7.1 HIGH | RTSP Null Pointer Dereference Denial-of-Service Vulnerability on TP-Link Tapo C100 and C10 |
| CVE-2026-8619 | 7.1 HIGH | Unauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR |
| CVE-2026-75619 | 6.9 MEDIUM | RTSP Heap Buffer Overflow Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101 |
No comments yet