Description
A denial-of-service
vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool
instruction handlng path in httpd does not properly synchronize or safely manage
concurrent systool operations. 





By sending
crafted systool instructions through the asynchronous request path, successful
exploitation may cause the httpd process or device management service to crash
and may result in temporary loss of access to the web management interface or
device reboot.
Published: 2026-08-07
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A concurrency flaw in the httpd service on TP‑Link Archer A6 v4 allows an authenticated attacker to send crafted systool instructions through the asynchronous request path. The flaw, identified as a race condition (CWE‑362), can cause the httpd process or the device management service to crash, leading to temporary loss of the web management interface or even a device reboot. The impact is a denial of service that affects the availability of the device’s management features.

Affected Systems

TP‑Link Archer A6 version 4 is affected. No other manufacturers or products are listed. The vulnerability is specific to the httpd component that handles systool instructions in this firmware build.

Risk and Exploitability

The CVSS score of 6.8 indicates a medium severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation activity. The attack requires valid credentials to the web interface and the ability to craft systool requests, implying that remote access to the management interface is a prerequisite. Once accessed, an attacker can trigger the race condition and force a service crash or reboot.

Generated by OpenCVE AI on August 7, 2026 at 21:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Archer A6 firmware to the latest version that addresses the httpd race condition.
  • If firmware update is not yet available, restrict access to the web management interface to trusted internal hosts and block external connections.
  • Consider disabling or limiting the httpd service on the device if management functionality is not required for your environment.

Generated by OpenCVE AI on August 7, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not properly synchronize or safely manage concurrent systool operations.  By sending crafted systool instructions through the asynchronous request path, successful exploitation may cause the httpd process or device management service to crash and may result in temporary loss of access to the web management interface or device reboot.
Title Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6
Weaknesses CWE-362
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-07T20:52:28.967Z

Reserved: 2026-05-19T16:30:33.339Z

Link: CVE-2026-9030

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T21:30:18Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')