Junglewise Threat Intelligence

CVE-2026-5511: TP-Link Archer AX72 information disclosure in diagnostic interface

CVE-2026-5511 · Severity: info · CVSS 4.6 · Published 2026-05-19

Vendors: TP-Link.

Executive brief

A vulnerability in the TP-Link Archer AX72 (SG) v1 router's web management interface could allow an administrator to view internal diagnostic command information. By providing invalid input to the network diagnostic tool, an authorized user can see technical details about how the diagnostic utility is structured. This issue does not expose sensitive customer data or system files, but it does reveal technical command syntax that should normally be hidden.

Technical details

An information disclosure vulnerability (CWE-209) exists in the network diagnostic feature of the TP-Link Archer AX72 (SG) v1 web management interface. The root cause is improper handling of invalid user input, which triggers error messages or help text revealing the command-line syntax and options of the underlying diagnostic utility. Exploitation requires local access and administrative privileges (PR:H). While an attacker can confirm the presence of specific utilities and their usage parameters, the vulnerability does not grant access to sensitive system data or allow for arbitrary command execution. The issue is resolved in firmware version 1.4.6 Build 20260112 rel.66206.

Affected products

  • TP-Link Archer AX72 (SG) v1 (Firmware versions prior to 1.4.6 Build 20260112 rel.66206)

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory
  • 2026-01-12: patched: Firmware build date for the fix

References