VYPR

AXE75

by TP-Link

CVEs (2)

  • CVE-2026-9044HigJul 31, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises…

  • CVE-2026-0631HigFeb 2, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device,…