Description
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters. 

Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability.
Published: 2026-07-31
Score: 8.5 High
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an OS command injection in the VPN module of TP-Link Archer AXE75 V1 routers that allows a nearby authenticated attacker to supply a specially crafted VPN client configuration file. The injection flaw stems from inadequate filtering of special characters, which can be exploited to run arbitrary operating‑system commands. Successful exploitation can give the attacker complete control over the device, jeopardizing router configuration integrity, network security posture, and service availability.

Affected Systems

TP-Link Systems Inc. Archer AXE75 V1 routers are impacted by this flaw. No further version granularity is specified beyond model V1.

Risk and Exploitability

The CVSS score of 8.5 signifies a high severity assessment. The EPSS score of less than 1% indicates a low current exploitation probability, however the vulnerability remains live and not yet listed in CISA KEV. Exploitation is likely limited to an adjacent, authenticated attacker on the same local network who can import a malicious VPN client configuration file; no remote unauthenticated vector is reported.

Generated by OpenCVE AI on August 2, 2026 at 03:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the most recent firmware version available from TP‑Link that resolves the VPN command injection flaw.
  • If firmware update is not immediately available, block or restrict the VPN subsystem so that unauthorized configuration imports are denied; consider disabling the import feature entirely.
  • Implement continuous monitoring of device logs for unexpected VPN configuration changes or execution of shell commands, and enforce strong authentication to limit who can import configuration files.

Generated by OpenCVE AI on August 2, 2026 at 03:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link axe75 V1
Vendors & Products Tp-link
Tp-link axe75 V1

Fri, 31 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters.  Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability.
Title Command Injection Vulnerability in OpenVPN of TP-Link Archer AXE75
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


Subscriptions

Tp-link Archer Axe75 Archer Axe75 Firmware Axe75 V1
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-04T03:56:21.578Z

Reserved: 2026-05-19T18:34:35.705Z

Link: CVE-2026-9044

cve-icon Vulnrichment

Updated: 2026-08-03T17:15:33.198Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-31T23:17:26.767

Modified: 2026-08-07T18:55:09.760

Link: CVE-2026-9044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:32:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')