← Back

Archer Axe75 Firmware

archer_axe75_firmware

Vendor: Tp Link • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tp Link
1Archer Axe75 Firmware
Aug 7, 2026
Jul 31, 2026
8.5 HIGH· v4
8.0 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a special...Show more
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters.  Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability.Show less
1Tp Link
1Archer Axe75 Firmware
Jun 17, 2026
Mar 9, 2026
8.5 HIGH· v4
8.0 HIGH· v3
N/A· v2
A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network access may be able to perform remote code execution (RCE) when the rou...Show more
A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network access may be able to perform remote code execution (RCE) when the router is configured with sysmode=ap. Successful exploitation results in root-level privileges and impacts confidentiality, integrity and availability of the device. This issue affects Archer AXE75 v1.6/v1.0: through 1.3.2 Build 20250107.Show less
1Tp Link
1Archer Axe75 Firmware
Jun 17, 2026
Jan 9, 2026
6.9 MEDIUM· v4
7.3 HIGH· v3
N/A· v2
Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary server file, leading to possible loss of critical system files and service...Show more
Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary server file, leading to possible loss of critical system files and service interruption or degraded functionality.This issue affects Archer AXE75 v1.6: ≤ build 20250107.Show less
1Tp Link
5Archer Ax3000 Firmware
Archer Ax5400 FirmwareArcher Axe75 Firmware+2 more
Jun 17, 2026
Jan 11, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN...Show more
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.Show less
1Tp Link
3Archer Ax3000 Firmware
Archer Ax5400 FirmwareArcher Axe75 Firmware
Jun 17, 2026
Jan 11, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands.