logo

CVE-2026-75616: TP-Link Archer C20 Command Injection Risks Full Device Compromise

ID: 2c7a6088-7fce-56d0-941d-669cc423e3b6

STIX ID: report--2c7a6088-7fce-56d0-941d-669cc423e3b6

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-08-24

Date Updated: 2026-08-25

Author: Do Son

...
...

TP-Link patched an authenticated OS command injection vulnerability (CVE-2026-75616, CVSS v4.0 score 8.5) affecting Archer C20 v6 firmware below specified EU/US/RU fixed builds; an authenticated admin could execute arbitrary system commands leading to full device compromise, no confirmed exploitation in the wild, and users are advised to update firmware, restrict admin access, change credentials, and disable remote management if unused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.