CVE-2026-30814 Details
Description
A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a crash and could allow arbitrary code execution, enabling modification of device state, exposure of sensitive data, or further compromise of device integrity. This issue affects AX53 v1.0: before 1.7.1 Build 20260213.
A stack-based buffer overflow vulnerability has been identified in the tmpServer module of the TP-Link Archer AX53 v1.0 router, prior to version 1.7.1 Build 20260213. This vulnerability allows an authenticated adjacent attacker to cause a segmentation fault and potentially execute arbitrary code by using a specially crafted configuration file. Exploitation of this vulnerability may lead to a device crash and could allow unauthorized code execution, enabling attackers to modify the device state, access sensitive data, or further compromise the device's integrity.
Users are advised to update to the latest firmware version, 1.7.1 Build 20260213, available on the TP-Link official website. Note that this version upgrade is irreversible.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2302 | CVE | |
| https://talosintelligence.com/vulnerability_reports/ | TPLink | Third Party Advisory |
| https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/my/support/download/archer-ax53/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5055/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-121 | Stack-based Buffer Overflow | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link archer ax53 firmware | < 1.7.1 |
CPE
Remediation
| |
| tp-link archer ax53 | 1.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 25, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 7, 2026 | CVE Modified | CVE |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Apr 8, 2026 | New CVE Received | TPLink |