HIGH🇵🇱 Wersja polska

CVE-2026-0834

CVSS 7.2v4.0pub. 2026-01-21upd. 2026-04-28

Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials. Attackers on the adjacent network can remotely trigger factory resets and reboots without credentials, causing configuration loss and interruption of device availability. This issue affects Archer C20 v6.0 < V6_251031, Archer C20 v5 <EU_V5_260317 or < US_V5_260419 Archer AX53 v1.0 < V1_251215 TL-WR841N v13 < 0.9.1 Build 20231120 Rel.62366

CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Tp Link Archer Ax53

    HW
    Tp-Link
    all versions
  • Tp Link Archer Ax53 Firmware

    OS
    Tp-Link
    1.0
  • Tp Link Archer C20

    HW
    Tp-Link
    all versions
  • Tp Link Archer C20 Firmware

    OS
    Tp-Link
    6.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-30818HIGH8.5same product

An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticate...

CVE-2026-30815HIGH8.5same product

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticate...

CVE-2026-30814HIGH7.3same product

A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adja...

CVE-2025-15608HIGH7.7same product

This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the devic...

CVE-2025-15607HIGH7.3same product

A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input hand...