Executive brief
A security vulnerability exists in the TP-Link Archer AX53, a popular Wi-Fi 6 router used in homes and small offices. An attacker who has already gained access to the local network can take full control of the device by uploading a malicious configuration file. This could allow them to monitor internet traffic, steal sensitive information, or disable the network entirely.
Technical details
An OS command injection vulnerability exists in the dnsmasq module of the TP-Link Archer AX53 v1.0 router. The flaw is rooted in insufficient input validation when processing configuration restore files, specifically involving the 'dhcpscript' parameter. An authenticated attacker located on the adjacent network (LAN) can exploit this by uploading a specially crafted configuration file to execute arbitrary system commands with elevated privileges. Successful exploitation leads to full system compromise, including the ability to modify device settings and access sensitive data. The issue is resolved in firmware version 1.7.1 Build 20260213 and later.
Affected products
- TP-Link Archer AX53 v1.0 before 1.7.1 Build 20260213
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-02-13: patched: Firmware build date for the fix