Description
A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient validation of externally supplied DHCP option data. An adjacent attacker may exploit this vulnerability by supplying crafted DHCP responses, potentially resulting in unauthorized command execution during device initialization or provisioning workflows. This typically occurs when the device is in a factory-default or unconfigured state. Successful exploitation may allow an adjacent, unauthenticated attacker to execute arbitrary commands with elevated privileges, potentially leading to full compromise of the affected device and unauthorized administrative control.
CVSS breakdown
CVSS 4.0
Attack Vector
Adjacent
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Confidentiality (Vulnerable System)
High
Integrity (Vulnerable System)
High
Availability (Vulnerable System)
High
Confidentiality (Subsequent System)
None
Integrity (Subsequent System)
None
Availability (Subsequent System)
None
Affected products
- TP-Link Systems Inc. / Archer C20 v50 – EU_V5_260317
- TP-Link Systems Inc. / Archer C20 v50 – US_V5_260419
- TP-Link Systems Inc. / Archer C20 v60 – V6_260608
- TP-Link Systems Inc. / Archer MR200 v070 – 1.3.0 Build 250605
- TP-Link Systems Inc. / Archer MR200 v80 – 1.5.0 Build 260605
- TP-Link Systems Inc. / Archer MR402 v10 – 1.5.0 Build 260605
- TP-Link Systems Inc. / Archer VR2100 v10 – EU_V1_260330
- TP-Link Systems Inc. / TL-MR6400 v70 – 1.7.0 Build 260413
References
- MISChttps://www.tp-link.com/en/support/download/archer-c20/
- MISChttps://www.tp-link.com/en/support/download/archer-mr402/#Firmware
- MISChttps://www.tp-link.com/en/support/download/archer-mr200/#Firmware
- MISChttps://www.tp-link.com/en/support/download/tl-mr6400/v7/#Firmware
- MISChttps://www.tp-link.com/en/support/download/archer-vr2100/#Firmware
- MISChttps://www.tp-link.com/us/support/download/archer-c20/
- MISChttps://www.tp-link.com/us/support/faq/5141/
- MISChttps://mattg.systems/posts/cve-2026-11834/