Command Injection in Router Web Management Interface
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.5epss 1.9%
from disclosure to weapon3 days
Published on NVDAug 19
1st PoC+3d
exploitation probability
1.9%top 22% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation to execute arbitrary system commands, potentially resulting in full device compromise.
Successful exploitation may allow arbitrary command execution with elevated privileges, compromising the confidentiality, integrity, and availability of the affected device and network traffic passing through it.
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
TP-Link Systems Inc. · Archer C20 v6public PoCs found — 1
githubgithub.com/totekuh/CVE-2026-75616★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.