CVE-2026-30817 Details
Description
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.
A vulnerability in the OpenVPN module of the TP-Link Archer AX53 V1.0 router, prior to version 1.7.1 Build 20260213, allows an authenticated adjacent attacker to read arbitrary files by processing a malicious configuration file. This exploitation could lead to unauthorized access to sensitive information stored on the device.
Users are advised to update to the latest firmware version, 1.7.1 Build 20260213, available on the TP-Link official website. Note that this version upgrade is irreversible.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2305 | CVE | |
| https://talosintelligence.com/vulnerability_reports/ | TPLink | Third Party Advisory |
| https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/my/support/download/archer-ax53/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5055/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-610 | Externally Controlled Reference to a Resource in Another Sphere | [email protected] |
| CWE-15 | External Control of System or Configuration Setting | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link archer ax53 firmware | < 1.7.1 |
CPE
Remediation
| |
| tp-link archer ax53 | 1.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 25, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 7, 2026 | CVE Modified | CVE |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Apr 8, 2026 | New CVE Received | TPLink |