An OS command injection vulnerability in the OpenVPN module
of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification of configuration files, disclosure of sensitive information, or further compromise of device integrity.
This issue affects AX53 v1.0: before 1.7.1 Build 20260213.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link archer Ax53
Tp-link archer Ax53 Firmware |
|
| CPEs | cpe:2.3:h:tp-link:archer_ax53:1.0:*:*:*:*:*:*:* cpe:2.3:o:tp-link:archer_ax53_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tp-link archer Ax53
Tp-link archer Ax53 Firmware |
|
| Metrics |
cvssV3_1
|
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link ax53 V1 |
|
| Vendors & Products |
Tp-link
Tp-link ax53 V1 |
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification of configuration files, disclosure of sensitive information, or further compromise of device integrity. This issue affects AX53 v1.0: before 1.7.1 Build 20260213. | |
| Title | OS Command Injection Vulnerability in OpenVPN Module in TP-Link AX53 | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published: 2026-04-08T17:52:29.336Z
Updated: 2026-04-09T03:56:16.458Z
Reserved: 2026-03-05T17:35:52.174Z
Link: CVE-2026-30815
Updated: 2026-04-08T19:11:35.349Z
Status : Analyzed
Published: 2026-04-08T19:25:20.320
Modified: 2026-04-14T16:19:40.307
Link: CVE-2026-30815
No data.