Junglewise Threat Intelligence

CVE-2026-5363: TP-Link Archer C7 inadequate encryption in uhttpd modules

CVE-2026-5363 · Severity: high · CVSS 8.8 · Published 2026-04-16

Vendors: TP-Link.

Executive brief

TP-Link Archer C7 routers use weak encryption when transmitting administrator passwords during the login process. An attacker on the same local network could intercept this traffic and crack the password, gaining full control over the router's settings and security. This could lead to unauthorized access to the network or disruption of internet services.

Technical details

The TP-Link Archer C7 (v5 and v5.8) web interface utilizes the uhttpd module to perform client-side encryption of administrator passwords using RSA-1024. Due to the relatively weak bit-length of the RSA key, an attacker positioned on the adjacent network (e.g., local Wi-Fi or LAN) can intercept the login traffic and perform a brute-force or factorization attack to recover the plaintext password. This vulnerability (CWE-326) allows for full device compromise. The issue affects firmware builds through 20220715. While the vendor has listed the product as End-of-Life (EOL), users are advised to check for firmware updates or replace the hardware.

Affected products

  • TP-Link Archer C7 v5 and v5.8 through Build 20220715

Timeline

  • 2026-04-15: disclosed: CVE received from TP-Link
  • 2026-04-16: advisory: NVD publication date

References

Related threats