TP-Link: Ten Vulnerabilities Including Command Injection and DoS Disclosed in August 2026 Batch
TP-Link disclosed ten vulnerabilities from August 24-28, 2026, affecting routers and smart home devices, including critical command injection and denial-of-service flaws.

Key findings
- Ten vulnerabilities disclosed in TP-Link devices between August 24-28, 2026, including high-severity command injection and DoS flaws.
- Multiple Archer routers vulnerable to command injection (CVE-2026-9254, CVE-2026-16348, CVE-2026-78541), allowing root command execution.
- TP-Link Kasa devices affected by insufficient crypto protections (CVE-2026-76784), enabling local network attacks.
- Denial-of-service and buffer overflow vulnerabilities found in TL-WR841N v14 and TL-MR100 V3.20.
- Mesh systems like Deco XE75 vulnerable due to hard-coded cryptographic keys (CVE-2026-15469).
- TP-Link has released firmware updates for all affected models; users urged to patch promptly.
On August 28, 2026, TP-Link disclosed a batch of ten vulnerabilities affecting various router models, with a significant cluster of high-severity flaws impacting command injection and denial-of-service vectors. The vulnerabilities were disclosed between August 24 and August 28, 2026, spanning four days and highlighting critical security weaknesses in several TP-Link product lines. These disclosures underscore the ongoing need for users to maintain up-to-date firmware to protect against potential exploitation.
Several high-severity command injection vulnerabilities were detailed, impacting multiple Archer router models. CVE-2026-9254, disclosed on August 24, 2026, affects the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1, allowing LAN-based attackers to inject arbitrary commands with root privileges due to improper filtering. Similarly, CVE-2026-16348, also disclosed on August 24, 2026, permits an authenticated attacker with administrative access to execute arbitrary system commands via a VPN connection on Archer BE800 V1. Another command injection flaw, CVE-2026-78541, disclosed on August 24, 2026, affects the parent-control module of TP-Link Archer BE3600 V1, allowing an authenticated adjacent attacker to store crafted profile names containing shell metacharacters, leading to unsafely processed daily cloud reports and potential command execution. Cyber Security News
Further compounding the command injection issues, CVE-2026-80712, disclosed on August 28, 2026, relates to a Linux kernel vulnerability in the spi-qpic-snand driver, which, while not directly a TP-Link product vulnerability, was part of a larger batch of kernel disclosures. This vulnerability involves writing a feature value before executing a SET_FEATURE command, potentially leading to unintended command execution. Vypr Intelligence
In addition to command injection, a critical vulnerability related to insufficient cryptographic protections was found in TP-Link Kasa smart home devices. CVE-2026-76784, disclosed on August 26, 2026, allows an adjacent network attacker to intercept, replay, or forge local device communication protocols, potentially leading to unauthorized device control or denial-of-service conditions. This vulnerability carries a high severity rating. Cyber Security News
The batch also includes several denial-of-service vulnerabilities affecting the TL-WR841N v14 model. CVE-2026-76650 and CVE-2026-76649, both disclosed on August 28, 2026, involve NULL pointer dereferences in the UPnP service when processing specific SOAP requests, which could lead to unexpected process termination or instability. Furthermore, CVE-2026-76651, also disclosed on August 28, 2026, is a medium-severity buffer overflow vulnerability in the embedded HTTP service when processing multipart/form-data requests, potentially allowing memory corruption.
A high-severity pre-authentication stack-based buffer overflow vulnerability, CVE-2026-75118, was disclosed on August 28, 2026, affecting the http_gdpr_decrypt function of TL-MR100 V3.20. Insufficient bounds checking of encrypted requests to the /cgi/login endpoint could allow an adjacent unauthenticated attacker to trigger memory corruption.
Finally, CVE-2026-15469, disclosed on August 24, 2026, highlights a vulnerability in the mesh functionality of Deco XE75 v3, XE5300 v3.6, and WE10800 v3.6 due to a hard-coded RSA-512 mesh group private key used for node authentication. An attacker obtaining the firmware could exploit this to authenticate as a legitimate node. Vypr Intelligence
TP-Link has released firmware updates for all affected models to address these vulnerabilities. Users are strongly advised to update their devices to the latest firmware versions to mitigate the risks associated with these disclosures. The wide range of affected products and vulnerability types underscores the importance of consistent security patching across TP-Link's diverse product ecosystem.
The disclosed vulnerabilities span critical areas including command injection, buffer overflows, denial-of-service, and cryptographic weaknesses. The command injection flaws, in particular, pose a significant risk, potentially allowing attackers to gain root-level access to affected routers. The timely disclosure and release of patches by TP-Link are crucial for protecting users from these threats.
The batch of vulnerabilities includes a mix of pre-authentication and authenticated attack vectors, affecting both consumer-grade routers and smart home devices. The presence of hard-coded cryptographic keys and insufficient cryptographic protections in local communication protocols are particularly concerning for the security of connected home environments.
Users should prioritize updating firmware for their TP-Link devices, paying close attention to advisories from TP-Link and security researchers. The span of affected devices, from older models like the TL-WR841N to newer mesh systems like Deco XE75, indicates a broad need for vigilance.
The Linux kernel vulnerability, CVE-2026-80712, while part of a larger kernel disclosure, is included in this batch and highlights the interconnectedness of system-level security. Prompt patching of both the kernel and device firmware is essential.
The vulnerabilities were disclosed across a four-day period, with a concentration on August 24 and August 28, 2026. This clustering suggests a coordinated disclosure event by researchers or security firms.
The command injection vulnerabilities, such as CVE-2026-9254 and CVE-2026-16348, are particularly severe, enabling attackers to execute arbitrary commands with root privileges. This could lead to full device compromise, credential theft, and further network infiltration.
The hard-coded cryptographic key in the mesh functionality (CVE-2026-15469) is a serious flaw that could allow an attacker to impersonate legitimate mesh nodes, potentially disrupting network operations or gaining unauthorized access.
The denial-of-service vulnerabilities in the TL-WR841N v14, such as CVE-2026-76650 and CVE-2026-76649, could render the affected routers inoperable, disrupting internet connectivity for users.
The buffer overflow vulnerabilities, including CVE-2026-76651 and CVE-2026-75118, present risks of memory corruption and potential code execution, depending on the specific exploitation context.
TP-Link has provided firmware updates to address all these issues, and users should ensure their devices are running the latest available versions. The broad impact across multiple product lines necessitates a proactive approach to security management for TP-Link customers.