Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
embedded-device-vulnerabilitywidely-deployed-product-advisory

TP-Link Archer AX53 Flaws Enable Command Injection via OpenVPN and dnsmasq

Updated 29d agoFirst seen Apr 8, 20266 sources

TP-Link Archer AX53 v1.0 routers were found to contain two high-severity OS command injection vulnerabilities, tracked as CVE-2026-30815 and CVE-2026-30818, affecting the device's OpenVPN and dnsmasq modules. In both cases, an authenticated attacker on an adjacent network can supply a specially crafted configuration file to trigger arbitrary command execution because of insufficient input validation, a weakness classified as CWE-78.

Successful exploitation could let an attacker alter router configuration, access sensitive information, and undermine overall device integrity and availability. The flaws affect Archer AX53 v1.0 firmware releases prior to 1.7.1 Build 20260213, and the CVSS v4.0 assessments indicate low attack complexity under adjacent-network conditions with high impact across confidentiality, integrity, and availability.

Share:
TP-Link Archer AX53 Flaws Enable Command Injection via OpenVPN and dnsmasq
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 8, 20263mo ago

CVE-2026-30818 disclosed for AX53 dnsmasq module command injection

A CVE entry disclosed an OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0. The flaw allows an authenticated adjacent attacker to execute arbitrary code via a specially crafted configuration file on firmware versions before 1.7.1 Build 20260213.

CVE-2026-30815 disclosed for AX53 OpenVPN module command injection

A CVE entry disclosed an OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0. The flaw allows an authenticated adjacent attacker to execute system commands via a specially crafted configuration file on firmware versions before 1.7.1 Build 20260213.

Feb 13, 20264mo ago

TP-Link publishes AX53 advisory covering five vulnerabilities

TP-Link published a security advisory for Archer AX53 covering five vulnerabilities: CVE-2026-30814, CVE-2026-30815, CVE-2026-30816, CVE-2026-30817, and CVE-2026-30818. The advisory coincided with the 2026-02-13 firmware release and expanded the known scope beyond the two CVEs already captured in the timeline.

Security Advisory on Multiple Vulnerabilities on Archer AX53 (CVE-2026-30814, CVE-2026-30815, CVE-2026-30816, CVE-2026-30817, CVE-2026-30818) | TP-Link

TP-Link fixes AX53 command injection flaws in firmware 1.7.1 Build 20260213

TP-Link Archer AX53 v1.0 firmware version 1.7.1 Build 20260213 became the first version not affected by two OS command injection vulnerabilities in the router's OpenVPN and dnsmasq modules, indicating the issues were addressed by that release.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Affected products
1 linked
Archer Ax53
Organizations
2 linked
Cisco SystemsTP-Link
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.