Executive brief
A security vulnerability exists in the TP-Link Archer AX53 router, a device used to provide Wi-Fi and network connectivity. An attacker already on the local network could exploit this flaw to read private files from the router's internal storage. This could lead to the exposure of sensitive configuration data or system information, potentially compromising the security of the home or office network.
Technical details
An external configuration control vulnerability (CWE-15/CWE-610) exists in the OpenVPN module of the TP-Link Archer AX53 v1.0 router. The flaw is triggered when the device processes a specially crafted malicious configuration file during a configuration restore or setup process. An authenticated attacker located on the adjacent network (local LAN) can exploit this to perform arbitrary file reads from the underlying filesystem. This could result in the disclosure of sensitive system files or credentials. The issue is resolved in firmware version 1.7.1 Build 20260213 and later.
Affected products
- TP-Link Archer AX53 v1.0 before 1.7.1 Build 20260213
Timeline
- 2026-04-08: advisory: Initial disclosure by TP-Link and NVD
- 2026-02-13: patched: Firmware build date for the fix