← Vulnerability feed

Vulnerability record · CVE-2026-30815 · published 8 April 2026

CVE-2026-30815: Tp-link archer ax53 firmware os command injection vulnerability

Tp Link · Archer Ax53 Firmware

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification of configuration files, disclosure of sensitive information, or further compromise of device integrity. This issue affects AX53 v1.0: before 1.7.1 Build 20260213.

8.5 CVSS 4.0 High EPSS 3.1% · top 12.9% CWE-78 · OS command injection
8.5CVSS 4.0 base score
3.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
25 Jul 2026Last modified by NVD

Description

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification of configuration files, disclosure of sensitive information, or further compromise of device integrity. This issue affects AX53 v1.0: before 1.7.1 Build 20260213.

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-30815 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-62673Tp-link archer ax53 firmware heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation faul…EPSS 0.55%8.5CVE-2026-30818Tp-link archer ax53 firmware os command injection vulnerabilityAn OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrar…EPSS 2.6%7.7CVE-2025-15608Tp-link archer ax53 firmware stack-based buffer overflow vulnerabilityThis vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalid…EPSS 0.64%7.3CVE-2026-30814Tp-link archer ax53 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation…EPSS 0.56%7.3CVE-2025-15607Tp-link archer ax53 firmware command injection vulnerabilityA command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbit…EPSS 2.0%7.3CVE-2025-58455Tp-link archer ax53 firmware heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…EPSS 0.40%7.3CVE-2025-59482Tp-link archer ax53 firmware heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…EPSS 0.40%7.3CVE-2025-59487Tp-link archer ax53 firmware heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…EPSS 0.40%

Source: NIST National Vulnerability Database (record CVE-2026-30815), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.