A vulnerability was found in TP-Link AXE75. It has been classified as very critical. Impacted is an unknown function of the component VPN Module. This manipulation causes os command injection.

The identification of this vulnerability is CVE-2026-9044. It is possible to initiate the attack remotely. There is no exploit available.