vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool
instruction handlng path in httpd does not properly synchronize or safely manage
concurrent systool operations.
By sending
crafted systool instructions through the asynchronous request path, successful
exploitation may cause the httpd process or device management service to crash
and may result in temporary loss of access to the web management interface or
device reboot.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 10 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 08 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link archer A6 V4 |
|
| Vendors & Products |
Tp-link
Tp-link archer A6 V4 |
Fri, 07 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not properly synchronize or safely manage concurrent systool operations. By sending crafted systool instructions through the asynchronous request path, successful exploitation may cause the httpd process or device management service to crash and may result in temporary loss of access to the web management interface or device reboot. | |
| Title | Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6 | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-08-10T18:23:58.299Z
Reserved: 2026-05-19T16:30:33.339Z
Link: CVE-2026-9030
Updated: 2026-08-10T17:28:51.496Z
Status : Received
Published: 2026-08-07T21:17:30.370
Modified: 2026-08-10T19:17:36.480
Link: CVE-2026-9030
No data.
OpenCVE Enrichment
Updated: 2026-08-08T20:40:19Z
-
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')