CVE-2026-11834
Last modified
CVE-2026-11834 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient validation of externally supplied DHCP option data. An adjacent attacker may exploit this vulnerability by supplying crafted DHCP responses, potentially resulting in unauthorized command execution during device initialization or provisioning workflows. This typically occurs when the device is in a factory-default or unconfigured state. Successful exploitation may allow an adjacent, unauthenticated attacker to execute arbitrary commands with elevated privileges, potentially leading to full compromise of the affected device and unauthorized administrative control.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient validation of externally supplied DHCP option data. An adjacent attacker may exploit this vulnerability by supplying crafted DHCP responses, potentially resulting in unauthorized command execution during device initialization or provisioning workflows. This typically occurs when the device is in a factory-default or unconfigured state. Successful exploitation may allow an adjacent, unauthenticated attacker to execute arbitrary commands with elevated privileges, potentially leading to full compromise of the affected device and unauthorized administrative control.
Metrics
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| TP-Link Systems Inc. | Archer MR200 v07 | < 1.3.0 Build 250605 |
| TP-Link Systems Inc. | Archer MR200 v8 | < 1.5.0 Build 260605 |
| TP Link Systems Inc. | Archer MR402 v1 | < 1.5.0 Build 260605 |
| TP-Link Systems Inc. | Archer VR2100 v1 | < EU_V1_260330 |
| TP-Link Systems Inc. | Archer C20 v5 | < EU_V5_260317; < US_V5_260419 |
| TP-Link Systems Inc. | Archer C20 v6 | < V6_260608 |
| TP-Link Systems Inc. | TL-MR6400 v7 | < 1.7.0 Build 260413 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-11834?
How severe is CVE-2026-11834?
How do I fix CVE-2026-11834?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-11825Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-11826OpenPLC_v3 contains a heap-based buffer overflow in the getD…8.8
- CVE-2026-11827GitLab has remediated an issue in GitLab EE affecting all ve…4.9
- CVE-2026-1183HTML injection vulnerability in multiple Botble products suc…5.1
- CVE-2026-11832Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl d…9.1
- CVE-2026-11833Overview: A vulnerability has been found in FAST/TOOLS and …8.2
- CVE-2026-11835Time-of-check time-of-use (TOCTOU) vulnerability combined wi…5.6
- CVE-2026-11836Insufficient verification of data authenticity in Caliptra C…1.8
- CVE-2026-11837A local privilege escalation vulnerability was found in the …7.3
- CVE-2026-11839Unrestricted upload of file with dangerous type vulnerabilit…9.9
- CVE-2026-1184GitLab has remediated an issue in GitLab EE affecting all ve…7.5
- CVE-2026-11841An attacker may perform unauthenticated read and write opera…9.4
Are you affected by CVE-2026-11834?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
