Impact
The Archer AX90 v1’s TDDPv2 service at /usr/bin/tddp contains a command‑injection flaw in its setProductVer command handler. An unauthenticated attacker adjacent to the device can trigger this flaw during boot, allowing the execution of arbitrary operating system commands with root privileges. This weakness falls under CWE‑78, and because it escalates to full system compromise, it presents a severe risk of data loss, device hijacking, and further lateral movement within the network. The high impact is that an attacker can gain complete control of the device with no authentication required.
Affected Systems
TP‑Link Systems Inc. Archer AX90 v1 (new firmware releases for this device model are available through TP‑Link’s official support pages). No other products or versions are listed as affected.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity vulnerability; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The lack of authentication and the requirement that the attacker be on an adjacent network make exploitation straightforward for local network attackers. Once the TDDPv2 service is invoked at boot, the attacker can execute any command as root, effectively taking full control of the device.
OpenCVE Enrichment