OS command injection in the TP-Link Archer C20 v6 web management interface

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-75616?

CVE-2026-75616 is a vulnerability classified as Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), affecting Archer C20 v6 (affected versions: < EU_0.9.1 Build 260811, < US_0.9.1 Build 260812, and other affected versions). This vulnerability is rated High, with a CVSS score of 8.5. Current sources do not report this vulnerability as exploited.

Overview

Original source data

An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation to execute arbitrary system commands, potentially resulting in full device compromise. Successful exploitation may allow arbitrary command execution with elevated privileges, compromising the confidentiality, integrity, and availability of the affected device and network traffic passing through it.

Affected products and scope

TP-Link identifies the following Archer C20 hardware V6 branches as affected:

  • Archer C20 (EU): firmware < EU_0.9.1 Build 260811.
  • Archer C20 (US): firmware < US_0.9.1 Build 260812.
  • Archer C20 (RU): firmware < RU_0.9.1 Build 260812.

The normalized record sets the default status to unaffected, but assessment must use the exact hardware version, regional branch, and firmware build. TP-Link's download pages list Archer C20(EU)_V6_0.9.1 Build 260811 for the EU branch and Archer C20(CPI)_V6.46_0.9.1 Build 260812 for the US branch, with security improvements described for those releases. The available evidence does not provide a separate RU download page to confirm more than the RU boundary listed above.

Technical details

This is a CWE-78 OS command injection flaw in the Archer C20 v6 firmware web management interface. During certain WAN-related configuration operations, administrator-controlled input is not sufficiently validated or neutralized before reaching system command execution logic. The available evidence does not identify the parameter, endpoint, shell, or function involved, so the exploit syntax and exact command construction remain unknown. Exploitation requires authenticated administrator privileges and adjacent network reachability; no additional user interaction is required and the record describes low complexity. Successful exploitation could execute arbitrary commands with elevated privileges on the router. The affected firmware scope and regional branches are listed separately in affected_summary.

Exploitability

  • Network reachability: access from an adjacent network to the web management interface is required.
  • Authentication: an authenticated administrator account with high privileges is required.
  • Interaction and complexity: no additional user interaction is required; the record describes low exploitation complexity.
  • Public status: the record provides public_exploit: false and no known-exploited flag. This does not prove that exploitation has never occurred.
  • No specific exploit, campaign, victim, or intrusion indicator is identified in the available evidence.

Technical impact

Successful exploitation could execute arbitrary commands with elevated privileges on Archer C20 v6. The technical consequences include loss of confidentiality, integrity, and availability for the device and possible interference with network traffic passing through the router. Because a router can control traffic flows, compromise could plausibly cause service disruption or altered network behavior, but the available evidence does not establish impact to other devices. The flaw requires authenticated administrator privileges and adjacent network access, so it is not described as unauthenticated Internet-accessible compromise. No specific breach or data exposure is confirmed.

Business impact

  • A compromised router could have its configuration changed, lose service availability, or be used to maintain unauthorized control.
  • Elevated command execution could expose, alter, or destroy device data and operational state.
  • Network traffic passing through the router could be affected in confidentiality, integrity, or availability if the device is controlled by an attacker.
  • The flaw requires an authenticated administrator account, so protecting administrative credentials remains important, but it does not replace firmware remediation.
  • The record does not identify a specific data breach, attack campaign, or confirmed incident.

Remediation

  1. Update affected Archer C20 hardware V6 devices to the latest firmware TP-Link identifies as fixing the flaw, using the official support page for the device's purchase region.
  2. For the EU branch, TP-Link lists Archer C20(EU)_V6_0.9.1 Build 260811. For the US branch, TP-Link lists Archer C20(CPI)_V6.46_0.9.1 Build 260812.
  3. For the RU branch, use the applicable TP-Link regional support page and verify that the installed firmware is not below the RU_0.9.1 Build 260812 boundary.
  4. Before upgrading, verify hardware version V6 and obtain firmware from the official TP-Link website for the purchase location. Do not power off the device during the upgrade.
  5. After updating, confirm the running firmware and review administrator accounts and WAN configuration changes. The advisory does not specify a workaround; if updating is not possible, obtain vendor-confirmed guidance rather than assuming an unverified mitigation.

Detection

  1. Inventory TP-Link Archer C20 devices and confirm hardware version V6, firmware region, and running firmware build.
  2. Compare each build with the regional boundaries in affected_summary; do not assess exposure from the model name alone.
  3. Identify web management interfaces reachable from adjacent networks and review accounts with administrator privileges, especially accounts that are no longer needed.
  4. Review administrative activity and WAN configuration changes during any suspected exposure period. This is general defensive review, not a vendor-confirmed indicator.
  5. The available evidence does not specify log events, command strings, or IOCs. The absence of matching log evidence does not prove that exploitation did not occur.
Sources (18)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan