CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-9044

unknowncovered by 1 sourcefirst seen 2026-07-31
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters. Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability.

⚡ Watch CVE-2026-9044

Get an email if CVE-2026-9044 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-9044

CVE.org record

Embed the live status

CVE-2026-9044 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-9044 status](https://www.csirts.com/badge/CVE-2026-9044)](https://www.csirts.com/cve/CVE-2026-9044)