Affected Vendors This Week:
- TP-Link: 2 CVEs
- ASUS: 1 CVE
- Cisco: 1 CVE
This week brought four new router and network device vulnerabilities, with a relatively quiet security landscape dominated by medium-to-low severity issues. However, two of the CVEs carry CVSS scores in the 7–8 range and warrant immediate attention from administrators managing affected hardware.
TP-Link: Dual Threats Across Multiple Models
TP-Link leads this week's disclosure list with two vulnerabilities affecting popular consumer and small business routers.
CVE-2026-9044 (CVSS 8.5) is the more concerning: an OS command injection flaw in the VPN module of TP-Link AXE75 V1 routers. While it requires an adjacent, authenticated attacker, the high CVSS score and remote code execution potential make this a priority for anyone deploying these devices. Check TP-Link's support portal for firmware updates immediately.
CVE-2026-12001 (CVSS 5.2) involves hardcoded credentials embedded in the firmware of four TP-Link models: TL-WR845N v4, TL-WR850N v3, Archer C20 v6, and Archer MR200 v5. Hardcoded credentials are persistent and notoriously difficult to remediate without full firmware replacement. If you manage any of these devices, prioritize firmware patching and verify credential change capabilities in your configuration management system.
ASUS: Race Condition in Armoury Crate
CVE-2026-16727 (CVSS 7.3) describes a race condition in ASUS Armoury Crate that allows local users to execute arbitrary code with elevated privileges. This is primarily a concern for ASUS router owners who use management or companion applications—verify whether your deployment includes Armoury Crate and apply vendor patches promptly.
Cisco: Unauthenticated FMC Access
CVE-2026-20316 (CVSS 5.3, Medium severity) affects Cisco Secure Firewall Management Center (FMC) software, potentially allowing unauthenticated remote login. While the CVSS is moderate, unauthorized access to centralized firewall management is a serious operational risk. Enterprise customers managing FMC instances should verify patch availability and apply updates as soon as feasible.
Recommendation: This is a manageable week for patching. Prioritize TP-Link CVE-2026-9044 and ASUS CVE-2026-16727 first, then address the hardcoded credential issue in TP-Link routers. Review your inventory against affected models and test patches in non-production environments before rollout.