Impact
A concurrency flaw in the httpd service on TP‑Link Archer A6 v4 allows an authenticated attacker to send crafted systool instructions through the asynchronous request path. The flaw, identified as a race condition (CWE‑362), can cause the httpd process or the device management service to crash, leading to temporary loss of the web management interface or even a device reboot. The impact is a denial of service that affects the availability of the device’s management features.
Affected Systems
TP‑Link Archer A6 version 4 is affected. No other manufacturers or products are listed. The vulnerability is specific to the httpd component that handles systool instructions in this firmware build.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation activity. The attack requires valid credentials to the web interface and the ability to craft systool requests, implying that remote access to the management interface is a prerequisite. Once accessed, an attacker can trigger the race condition and force a service crash or reboot.
OpenCVE Enrichment