Impact
An input validation flaw in the HTTP‑WRITEOEM handler allows a malicious user to send malformed data that the internal flash‑write logic does not properly sanitize. Processing this data can crash the httpd process, causing the device’s web interface to become unresponsive and leading to a denial‑of‑service condition. The vulnerability does not provide any privilege escalation or information disclosure capabilities beyond this service disruption.
Affected Systems
TP‑Link Archer A6 firmware version 4. The flaw is reported only for this device model and does not affect other TP‑Link products or firmware revisions.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widely known exploits yet. Attacks are likely to require authenticated access to the web interface, implying that an attacker must first log in or otherwise obtain valid credentials to exploit the flaw. The risk remains contingent on the availability of the credentialed user and the absence of mitigations such as disabling the vulnerable handler.
OpenCVE Enrichment