Executive brief
A security vulnerability exists in the TP-Link Archer AX53 router, a device used to provide Wi-Fi and networking for homes and small offices. An attacker already on the local network could take control of the device by uploading a malicious configuration file to the VPN settings. This could lead to the theft of sensitive data, modification of network settings, or a complete takeover of the router.
Technical details
An OS command injection vulnerability exists in the OpenVPN module of the TP-Link Archer AX53 v1.0 router. The flaw is caused by insufficient input validation when processing OpenVPN configuration files during a configuration restore process. Specifically, parameters such as 'client_connect', 'script_security', 'client_disconnect', and 'route_up' can be manipulated to execute arbitrary system commands. An attacker must be authenticated and located on the adjacent network to exploit this vulnerability. Successful exploitation allows for full system compromise, including the ability to modify configuration files and disclose sensitive information. The issue is resolved in firmware version 1.7.1 Build 20260213.
Affected products
- TP-Link Archer AX53 v1.0 before 1.7.1 Build 20260213
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-02-13: patched: Firmware build date for the fix
References
- https://talosintelligence.com/vulnerability_reports/
- https://www.tp-link.com/en/support/download/archer-ax53/v1/
- https://www.tp-link.com/my/support/download/archer-ax53/v1/
- https://www.tp-link.com/us/support/faq/5055/
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2303
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2307
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2308