← Vulnerability feed

Vulnerability record · CVE-2026-5363 · published 16 April 2026

CVE-2026-5363: Tp-link archer c7 firmware inadequate encryption strength vulnerability

Tp Link · Archer C7 Firmware

Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login.  An adjacent attacker with the ability to intercept network traffic could potentially perform a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext administrator password, leading to unauthorized access and compromise of the device configuration.  This issue affects Archer C7: through Build 20220715.

5.4 CVSS 4.0 Medium EPSS 0.11% · top 98.6% CWE-326 · Inadequate encryption strength
5.4CVSS 4.0 base score
0.11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login.  An adjacent attacker with the ability to intercept network traffic could potentially perform a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext administrator password, leading to unauthorized access and compromise of the device configuration.  This issue affects Archer C7: through Build 20220715.

CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-5363 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-9377TP-Link Archer C7 and TL-WR841N Parental Control OS Command InjectionAn OS command injection flaw (CWE-78) exists in the Parental Control page of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 routers, allowing an au…KEVEPSS 34%analysed7.5CVE-2015-3035TP-Link router directory traversal allows unauthenticated file readA path traversal flaw in the web interface of multiple TP-Link Archer and TL-WR/WDR router models lets a remote attacker read arbitrary files by plac…KEVEPSS 84%analysed6.5CVE-2023-50224TP-Link router httpd authentication bypass exposes stored credentialsThe httpd service on affected TP-Link router firmware contains an improper authentication flaw (CWE-290) that lets a network-adjacent attacker bypass…KEVEPSS 16%analysed9.8CVE-2020-35575Tp-link wa901nd firmware vulnerabilityA password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web pan…EPSS 7.6%8.0CVE-2023-39224Tp-link archer c7 firmware os command injection vulnerabilityArcher C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to…EPSS 0.40%4.5CVE-2023-2646Tp-link archer c7 firmware improper resource shutdown vulnerabilityA vulnerability has been found in TP-Link Archer C7v2 v2_en_us_180114 and classified as problematic. Affected by this vulnerability is an unknown fun…EPSS 0.32%9.8CVE-2017-11317Telerik UI for ASP.NET AJAX weak encryption enables arbitrary file uploadTelerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption. Because the encr…KEVEPSS 84%analysed9.8CVE-2017-1000486PrimeFaces weak encryption flaw leads to remote code executionPrimeFaces 5.x uses inadequate encryption strength (CWE-326), which allows an unauthenticated remote attacker to reach code execution. The flaw is ra…KEVEPSS 94%analysed

Source: NIST National Vulnerability Database (record CVE-2026-5363), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.