What is CVE-2026-9044?
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This flaw allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. Updating the router's firmware to the latest version is recommended.
Azərbaycanca: TP-Link AXE75 V1 routerlərinin VPN modulunda OS command injection zəifliyi aşkarlanıb. Bu boşluq qonşu şəbəkədəki autentifikasiya olunmuş təcavüzkara xüsusi hazırlanmış VPN konfiqurasiya faylını idxal etməklə cihazda ixtiyari əmrlər icra etməyə imkan verir. Routerin proqram təminatını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: TP-Link
FAQ2
What conditions must an attacker meet to exploit the CVE-2026-9044 vulnerability in the TP-Link AXE75 V1 router?
The attacker must be on an adjacent network and be authenticated on the device. Additionally, they need to import a specially crafted VPN client configuration file.
What measure is recommended to prevent the CVE-2026-9044 vulnerability?
Updating the router's firmware to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.