CVE Tools

CVSS 8.7 Unauthenticated RCE Impacts Multiple TP-Link Routers

Daily CyberSecurity (securityonline.info)

PatchTP-Link Routers

Our summary

TP-Link has disclosed CVE-2026-11834, a high-severity command injection flaw that can lead to unauthenticated remote code execution for TP-Link Systems Inc. Archer MR200 v07 devices with affected firmware builds: < 1.3.0 Build 250605, < 1.5.0 Build 260605, < EU_V1_260330, < EU_V5_260317, < US_V5_260419, < V6_260608 (+1 more). The issue stems from improper handling of externally provided DHCP options during device initialization, which can let a nearby attacker trigger arbitrary command execution without authentication. TP-Link reports no confirmed public exploitation yet, but the recommended mitigation is to upgrade to fixed releases such as 1.3.0 Build 250605 and 1.5.0 Build 260605 (and the corresponding EU/US builds listed by the vendor).

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store