AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-9030

MEDIUM · CVSS 6.8 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The httpd service on Archer A6 v4 is vulnerable to a denial-of-service attack due to improper synchronization in handling concurrent systool operations. Attackers can exploit this vulnerability by sending crafted systool instructions, potentially causing the httpd process or device management service to crash, leading to temporary loss of access to the web management interface or even a device reboot. Network administrators and users of Archer A6 v4 should prioritize this issue to mitigate potential disruptions in service.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-9030
Severity
MEDIUM
CVSS
6.8
EPSS
0.13%

Original NVD Description

A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not properly synchronize or safely manage concurrent systool operations.  By sending crafted systool instructions through the asynchronous request path, successful exploitation may cause the httpd process or device management service to crash and may result in temporary loss of access to the web management interface or device reboot.