CVE-2026-9030

MEDIUM CVSS 4.0: 6.8 EPSS 0.13%
Updated Aug 08, 2026
Tp-Link Systems Inc.
Parameter Value
CVSS 6.8 (MEDIUM)
Type CWE-362 (Race Condition)
Vendor Tp-Link Systems Inc.
Public PoC No

A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not properly synchronize or safely manage concurrent systool operations.  By sending crafted systool instructions through the asynchronous request path, successful exploitation may cause the httpd process or device management service to crash and may result in temporary loss of access to the web management interface or device reboot.

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products

tp-link systems inc.:archer a6 v4