Junglewise Threat Intelligence

CVE-2026-30818: TP-Link Archer AX53 OS command injection in dnsmasq

CVE-2026-30818 · Severity: high · CVSS 8 · Published 2026-04-08

Technologies: TP-Link Archer Ax53, TP-Link Archer Ax53 Firmware. Vendors: TP-Link.

Executive brief

A security vulnerability exists in the TP-Link Archer AX53, a popular Wi-Fi 6 router used in homes and small offices. An attacker who has already gained access to the local network can take full control of the device by uploading a malicious configuration file. This could allow them to monitor internet traffic, steal sensitive information, or disable the network entirely.

Technical details

An OS command injection vulnerability exists in the dnsmasq module of the TP-Link Archer AX53 v1.0 router. The flaw is rooted in insufficient input validation when processing configuration restore files, specifically involving the 'dhcpscript' parameter. An authenticated attacker located on the adjacent network (LAN) can exploit this by uploading a specially crafted configuration file to execute arbitrary system commands with elevated privileges. Successful exploitation leads to full system compromise, including the ability to modify device settings and access sensitive data. The issue is resolved in firmware version 1.7.1 Build 20260213 and later.

Affected products

  • TP-Link Archer AX53 v1.0 before 1.7.1 Build 20260213

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-02-13: patched: Firmware build date for the fix

References

Related threats