Executive brief
TP-Link Archer C7 routers use weak encryption when transmitting administrator passwords during the login process. An attacker on the same local network could intercept this traffic and crack the password, gaining full control over the router's settings and security. This could lead to unauthorized access to the network or disruption of internet services.
Technical details
The TP-Link Archer C7 (v5 and v5.8) web interface utilizes the uhttpd module to perform client-side encryption of administrator passwords using RSA-1024. Due to the relatively weak bit-length of the RSA key, an attacker positioned on the adjacent network (e.g., local Wi-Fi or LAN) can intercept the login traffic and perform a brute-force or factorization attack to recover the plaintext password. This vulnerability (CWE-326) allows for full device compromise. The issue affects firmware builds through 20220715. While the vendor has listed the product as End-of-Life (EOL), users are advised to check for firmware updates or replace the hardware.
Affected products
- TP-Link Archer C7 v5 and v5.8 through Build 20220715
Timeline
- 2026-04-15: disclosed: CVE received from TP-Link
- 2026-04-16: advisory: NVD publication date