← Vulnerability feed

Vulnerability record · CVE-2026-0834 · published 21 January 2026

CVE-2026-0834: Tp-link archer ax53 firmware authentication bypass by spoofing vulnerability

Tp Link · Archer Ax53 Firmware

Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials. Attackers on the adjacent network can remotely trigger factory resets and reboots without credentials, causing configuration loss and interruption of device availability. This issue affects Archer C20 v6.0 < V6_251031, Archer C20 v5 <EU_V5_260317 or < US_V5_260419 Archer AX53 v1.0 < V1_251215 TL-WR841N v13 < 0.9.1 Build 20231120 Rel.62366

7.2 CVSS 4.0 High EPSS 0.43% · top 64.7% CWE-290 · Authentication bypass by spoofing
7.2CVSS 4.0 base score
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials. Attackers on the adjacent network can remotely trigger factory resets and reboots without credentials, causing configuration loss and interruption of device availability. This issue affects Archer C20 v6.0 < V6_251031, Archer C20 v5 <EU_V5_260317 or < US_V5_260419 Archer AX53 v1.0 < V1_251215 TL-WR841N v13 < 0.9.1 Build 20231120 Rel.62366

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-0834 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-37284Tp-link archer c20 firmware improper authentication vulnerabilityImproper authentication vulnerability in Archer C20 firmware versions prior to 'Archer C20(JP)_V1_230616' allows a network-adjacent unauthenticated a…EPSS 0.41%8.6CVE-2025-62673Tp-link archer ax53 firmware heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation faul…EPSS 0.55%8.5CVE-2026-75616Tp-link archer c20 firmware os command injection vulnerabilityAn OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configurat…EPSS 2.8%8.5CVE-2026-30815Tp-link archer ax53 firmware os command injection vulnerabilityAn OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system c…EPSS 3.1%8.5CVE-2026-30818Tp-link archer ax53 firmware os command injection vulnerabilityAn OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrar…EPSS 2.6%7.7CVE-2025-15608Tp-link archer ax53 firmware stack-based buffer overflow vulnerabilityThis vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalid…EPSS 0.64%7.5CVE-2023-30383Tp-link archer c2 v1 firmware classic buffer overflow vulnerabilityTP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discov…EPSS 1.4%7.3CVE-2026-30814Tp-link archer ax53 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation…EPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2026-0834), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.