HIGH🇵🇱 Wersja polska

CVE-2026-30815

CVSS 8.5v4.0pub. 2026-04-08upd. 2026-07-25

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification of configuration files, disclosure of sensitive information, or further compromise of device integrity. This issue affects AX53 v1.0: before 1.7.1 Build 20260213.

CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Tp Link Archer Ax53

    HW
    Tp-Link
    1.0
  • Tp Link Archer Ax53 Firmware

    OS
    Tp-Link
    < 1.7.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
VPNCommand Injection
CWE
References

Related vulnerabilities

CVE-2026-30814HIGH7.3same product

A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adja...

CVE-2026-30818HIGH8.5same product

An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticate...

CVE-2025-15607HIGH7.3same product

A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input hand...

CVE-2025-15608HIGH7.7same product

This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the devic...

CVE-2025-59482HIGH7.3same product

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated ...