Description
A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot. 

Successful exploitation may result in complete device compromise through arbitrary command execution with root privileges.
Published: 2026-10-01
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Root Command Execution
Action: Immediate Patch
AI Analysis

Impact

The Archer AX90 v1’s TDDPv2 service at /usr/bin/tddp contains a command‑injection flaw in its setProductVer command handler. An unauthenticated attacker adjacent to the device can trigger this flaw during boot, allowing the execution of arbitrary operating system commands with root privileges. This weakness falls under CWE‑78, and because it escalates to full system compromise, it presents a severe risk of data loss, device hijacking, and further lateral movement within the network. The high impact is that an attacker can gain complete control of the device with no authentication required.

Affected Systems

TP‑Link Systems Inc. Archer AX90 v1 (new firmware releases for this device model are available through TP‑Link’s official support pages). No other products or versions are listed as affected.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity vulnerability; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The lack of authentication and the requirement that the attacker be on an adjacent network make exploitation straightforward for local network attackers. Once the TDDPv2 service is invoked at boot, the attacker can execute any command as root, effectively taking full control of the device.

Generated by OpenCVE AI on October 1, 2026 at 20:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Download and install the latest firmware for Archer AX90 v1 from TP‑Link’s official support site to include the vendor’s patch for the TDDPv2 command injection flaw.
  • Disable the TDDPv2 service (or the /usr/bin/tddp binary) via the router’s management interface or by removing the service if the firmware allows, to stop the vulnerable code from running at boot.
  • Segment the local network to isolate the router from untrusted adjacent devices, preventing an insider or rogue device from initiating the boot‑time command injection attack.

Generated by OpenCVE AI on October 1, 2026 at 20:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot.  Successful exploitation may result in complete device compromise through arbitrary command execution with root privileges.
Title TDDPv2 setProductVer Command Injection in Archer AX90
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-10-02T03:55:36.196Z

Reserved: 2026-09-01T22:24:51.457Z

Link: CVE-2026-84682

cve-icon Vulnrichment

Updated: 2026-10-01T18:58:32.440Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T19:17:24.960

Modified: 2026-10-02T04:18:09.383

Link: CVE-2026-84682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T21:00:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')