← Vulnerability feed

Vulnerability record · CVE-2026-30814 · published 8 April 2026

CVE-2026-30814: Tp-link archer ax53 firmware stack-based buffer overflow vulnerability

Tp Link · Archer Ax53 Firmware

A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a crash and could allow arbitrary code execution, enabling modification of device state, exposure of sensitive data, or further compromise of device integrity. This issue affects AX53 v1.0: before 1.7.1 Build 20260213.

7.3 CVSS 4.0 High EPSS 0.56% · top 55.7% CWE-121 · Stack-based buffer overflowCWE-787 · Out-of-bounds write
7.3CVSS 4.0 base score
0.56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
25 Jul 2026Last modified by NVD

Description

A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a crash and could allow arbitrary code execution, enabling modification of device state, exposure of sensitive data, or further compromise of device integrity. This issue affects AX53 v1.0: before 1.7.1 Build 20260213.

CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-30814 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-62673Tp-link archer ax53 firmware heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation faul…EPSS 0.55%8.5CVE-2026-30815Tp-link archer ax53 firmware os command injection vulnerabilityAn OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system c…EPSS 3.1%8.5CVE-2026-30818Tp-link archer ax53 firmware os command injection vulnerabilityAn OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrar…EPSS 2.6%7.7CVE-2025-15608Tp-link archer ax53 firmware stack-based buffer overflow vulnerabilityThis vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalid…EPSS 0.64%7.3CVE-2025-15607Tp-link archer ax53 firmware command injection vulnerabilityA command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbit…EPSS 2.0%7.3CVE-2025-58455Tp-link archer ax53 firmware heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…EPSS 0.40%7.3CVE-2025-59482Tp-link archer ax53 firmware heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…EPSS 0.40%7.3CVE-2025-59487Tp-link archer ax53 firmware heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…EPSS 0.40%

Source: NIST National Vulnerability Database (record CVE-2026-30814), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.