Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-11834

35
FAUCET Score

A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient validation of externally supplied DHCP option data. An adjacent attacker may exploit this vulnerability by supplying crafted DHCP responses, potentially resulting in unauthorized command execution during device initialization or provisioning workflows. This typically occurs when the device is in a factory-default or unconfigured state. Successful exploitation may allow an adjacent, unauthenticated attacker to execute arbitrary commands with elevated privileges, potentially leading to full compromise of the affected device and unauthorized administrative control.

First published: Jun 22, 2026Last modified: Jun 26, 2026

Impacted Technologies

VendorProductVersion(s)CPE
TP-Link Systems Inc.Archer C20 V5
>= 0, < EU_V5_260317, >= 0, < US_V5_260419CNA affecteddefault unaffected
TP-Link Systems Inc.Archer C20 V6
>= 0, < V6_260608CNA affecteddefault unaffected
TP-Link Systems Inc.Archer MR200 V07
>= 0, < 1.3.0 Build 250605CNA affecteddefault unaffected
TP-Link Systems Inc.Archer MR200 V8
>= 0, < 1.5.0 Build 260605CNA affecteddefault unaffected
TP Link Systems Inc.Archer MR402 V1
>= 0, < 1.5.0 Build 260605CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
ADJACENT
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.02%
Probability of exploitation in next 30 days
EPSS Percentile
59.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0102 is in the 97th percentile among its peer group of 61 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.4 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

mattg.systems / posts/cve-2026-11834
tp-link.com / en/support/download/archer-c20
tp-link.com / en/support/download/archer-mr200
tp-link.com / en/support/download/archer-mr402
tp-link.com / en/support/download/archer-vr2100
tp-link.com / en/support/download/tl-mr6400/v7
tp-link.com / us/support/download/archer-c20
tp-link.com / us/support/faq/5141