Description
An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation to execute arbitrary system commands, potentially resulting in full device compromise.






Successful exploitation may allow arbitrary command execution with elevated privileges, compromising the confidentiality, integrity, and availability of the affected device and network traffic passing through it.
Published: 2026-08-19
Score: 8.5 High
EPSS: 3.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS command injection flaw in the Archer C20 v6 firmware web management interface allows an authenticated administrator to inject and run arbitrary shell commands on the device, bypassing insufficient input validation during WAN configuration changes. The flaw enables full device compromise, granting complete control over confidentiality, integrity, and availability, and potentially exposing or disrupting network traffic.

Affected Systems

This issue affects devices from TP‑Link Systems Inc., specifically the Archer C20 router running firmware version 6. The vulnerability is present in the firmware shown in the official download links and relies on the web interface configuration endpoints.

Risk and Exploitability

The CVSS score of 8.5 marks this as high severity. The EPSS score of 1% indicates a low but non‑zero probability of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers would need administrator credentials or compromised network access to reach the web interface; the flaw is exploitable only once authenticated. Once accessed, the command injection can be triggered by suitable WAN‑related configuration requests, enabling arbitrary system commands with elevated privileges.

Generated by OpenCVE AI on August 20, 2026 at 22:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest version released by TP‑Link (e.g., v6.46 or newer).
  • Restrict the web management interface to a secure internal network or VPN and enforce strong, unique authentication for administrators.
  • Disable or limit WAN‑configuration features on the router when they are not required to reduce the attack surface.

Generated by OpenCVE AI on August 20, 2026 at 22:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link archer C20
Tp-link archer C20 Firmware
CPEs cpe:2.3:h:tp-link:archer_c20:6.0:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_c20_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tp-link archer C20
Tp-link archer C20 Firmware
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link archer C20 V6
Vendors & Products Tp-link
Tp-link archer C20 V6

Wed, 19 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation to execute arbitrary system commands, potentially resulting in full device compromise. Successful exploitation may allow arbitrary command execution with elevated privileges, compromising the confidentiality, integrity, and availability of the affected device and network traffic passing through it.
Title Command Injection in Router Web Management Interface
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Archer C20 Archer C20 Firmware Archer C20 V6
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-20T15:26:33.291Z

Reserved: 2026-08-17T23:56:24.056Z

Link: CVE-2026-75616

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T21:17:37.917

Modified: 2026-09-08T21:12:13.843

Link: CVE-2026-75616

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:16:15Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')