CVE-2026-9030 Details
Description
A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not properly synchronize or safely manage concurrent systool operations. By sending crafted systool instructions through the asynchronous request path, successful exploitation may cause the httpd process or device management service to crash and may result in temporary loss of access to the web management interface or device reboot.
A denial-of-service vulnerability has been identified in the HTTPD service on TP-Link Archer A6 routers, specifically in version 4. The issue arises because the asynchronous systool instruction handling does not properly synchronize or manage concurrent operations. Exploitation of this vulnerability involves sending crafted systool instructions through the asynchronous request path, which can cause the HTTPD process or device management service to crash. This may lead to a temporary loss of access to the web management interface or require the device to reboot.
Users are advised to update to the latest firmware version 1.15.10 Build 260625, available on the TP-Link website. This update enhances device security and stability and addresses the vulnerability. Instructions for downloading the firmware are provided on the TP-Link support page for the Archer A6 V4.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | TPLink |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | TPLink |