CVE-2026-5363 Details
Description
Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login. An adjacent attacker with the ability to intercept network traffic could potentially perform a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext administrator password, leading to unauthorized access and compromise of the device configuration. This issue affects Archer C7: through Build 20220715.
A vulnerability exists in the TP-Link Archer C7 models v5 and v5.8, specifically within the uhttpd modules, due to inadequate encryption strength. The web interface encrypts the admin password using RSA-1024 before transmission to the router. An adjacent attacker capable of intercepting network traffic could exploit this weakness by performing a brute-force or factorization attack on the 1024-bit RSA key to recover the plaintext password. This would lead to unauthorized access and compromise of the device's configuration. The vulnerability affects Archer C7 models through Build 20220715.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/us/support/faq/3562/ | TPLink | Not Applicable |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-326 | Inadequate Encryption Strength | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link archer c7 firmware | < 1.2.1 |
CPE
Remediation
| |
| tp-link archer c7 | 5.0 5.80 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 22, 2026 | Reanalysis | [email protected] |
| May 6, 2026 | Initial Analysis | [email protected] |
| Apr 16, 2026 | New CVE Received | TPLink |