CVE-2026-5511 Details
Description
In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user input, resulting in limited exposure of diagnostic command usage information. An authenticated attacker with administrative privileges could exploit this issue to confirm the presence of the diagnostic utility and view its valid command-line syntax and options. The exposed information is limited in scope and does not include sensitive system data.
A vulnerability exists in the web management interface of the TP-Link Archer AX72 (SG) v1 router. The issue arises in the network diagnostic feature, which fails to properly validate user input. This flaw allows an authenticated attacker with administrative privileges to exploit the vulnerability, confirming the presence of the diagnostic utility and accessing its command-line syntax and options. However, the exposed information is limited and does not include sensitive system data.
Users are advised to update their devices to the latest firmware version 1.4.6 Build 20260112, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/sg/support/download/archer-ax72/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5096/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-209 | Generation of Error Message Containing Sensitive Information | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link archer ax72 firmware | < 1.4.6 |
CPE
Remediation
| |
| tp-link archer ax72 | 1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Initial Analysis | [email protected] |
| May 19, 2026 | New CVE Received | TPLink |