Router CVE Weekly Digest — Jun 22–28, 2026

Published June 29, 2026 · Covering Jun 22–28, 2026 · RouterCVE Weekly Digest

4 CVEs 1 High

Affected Vendors This Week

  • Peplink: 1 CVE (High severity)
  • TP-Link: 1 CVE
  • ASUS: 1 CVE
  • OpenWrt / DD-WRT: 1 CVE

A quiet week on the router vulnerability front with just four new CVEs, though one critical access-control bypass deserves immediate attention from Peplink InControl 2 users.

Critical: Peplink Access-Control Bypass

CVE-2026-57920 (CVSS 7.7) affects Peplink InControl 2 through version 2.14.2 and allows attackers to bypass access-control rules on certain /rest/o/{orgId} endpoints using a semicolon injection technique. InControl 2 is commonly deployed as a centralized management platform for Peplink router fleets, making this a significant risk for multi-site organizations. Action: If you manage Peplink equipment, update to the latest firmware immediately and verify your InControl 2 instance is patched beyond 2.14.2.

Other Vulnerabilities This Week

CVE-2026-11834 (CVSS 8.7) identifies a command injection flaw in TP-Link router DHCP option processing. Despite its lack of assigned severity, the high CVSS score reflects real risk from insufficient validation of external DHCP data. CVE-2026-8918 affects ASUS Armoury Crate with a local privilege escalation path, while CVE-2026-53317 addresses a kernel-level DoS in MT76 WiFi drivers affecting OpenWrt and DD-WRT systems when stations are assigned invalid AIDs.

Check your vendor patch portals for updates, particularly for Peplink and TP-Link deployments.