Junglewise Threat Intelligence

CVE-2026-30814: TP-Link Archer AX53 stack overflow in tmpServer

CVE-2026-30814 · Severity: high · CVSS 8 · Published 2026-04-08

Technologies: TP-Link Archer Ax53, TP-Link Archer Ax53 Firmware. Vendors: TP-Link.

Executive brief

A security vulnerability exists in the TP-Link Archer AX53 v1.0 router, a device used for home and small office networking. An authenticated attacker on the same local network can exploit this flaw by uploading a malicious configuration file. If successful, this could allow the attacker to crash the device or take full control of it, potentially leading to the theft of sensitive data or unauthorized monitoring of network traffic.

Technical details

A stack-based buffer overflow (CWE-121) exists in the tmpServer module of the TP-Link Archer AX53 v1.0 router. The vulnerability is triggered during the processing of a specially crafted configuration file, specifically involving opcode 0x436. An attacker must be authenticated and located on the adjacent network (local network) to exploit this flaw. Successful exploitation allows for arbitrary code execution with high privileges on the device, which can lead to a complete compromise of device integrity, confidentiality, and availability. The issue is resolved in firmware version 1.7.1 Build 20260213 and later.

Affected products

  • TP-Link Archer AX53 v1.0 before 1.7.1 Build 20260213

Timeline

  • 2026-04-08: disclosed: Initial disclosure by TP-Link
  • 2026-04-08: advisory: NVD publication date
  • 2026-05-07: advisory: Cisco Talos advisory publication

References

Related threats