CVSS 8.7 Unauthenticated RCE Impacts Multiple TP-Link Routers
TP-Link has disclosed CVE-2026-11834, a high-severity command injection flaw that can lead to unauthenticated remote code execution for TP-Link Systems Inc. Archer MR200 v07 devices with affected firmware builds: < 1.3.0 Build 250605, < 1.5.0 Build 260605, < EU_V1_260330, < EU_V5_260317, < US_V5_260419, < V6_260608 (+1 more). The issue stems from improper handling of externally provided DHCP options during device initialization, which can let a nearby attacker trigger arbitrary command execution without authentication. TP-Link reports no confirmed public exploitation yet, but the recommended mitigation is to upgrade to fixed releases such as 1.3.0 Build 250605 and 1.5.0 Build 260605 (and the corresponding EU/US builds listed by the vendor).