TP-Link Archer AX53 v1.0 routers were found to contain two high-severity OS command injection vulnerabilities, tracked as CVE-2026-30815 and CVE-2026-30818, affecting the device's OpenVPN and dnsmasq modules. In both cases, an authenticated attacker on an adjacent network can supply a specially crafted configuration file to trigger arbitrary command execution because of insufficient input validation, a weakness classified as CWE-78.
Successful exploitation could let an attacker alter router configuration, access sensitive information, and undermine overall device integrity and availability. The flaws affect Archer AX53 v1.0 firmware releases prior to 1.7.1 Build 20260213, and the CVSS v4.0 assessments indicate low attack complexity under adjacent-network conditions with high impact across confidentiality, integrity, and availability.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A CVE entry disclosed an OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0. The flaw allows an authenticated adjacent attacker to execute arbitrary code via a specially crafted configuration file on firmware versions before 1.7.1 Build 20260213.
A CVE entry disclosed an OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0. The flaw allows an authenticated adjacent attacker to execute system commands via a specially crafted configuration file on firmware versions before 1.7.1 Build 20260213.
TP-Link published a security advisory for Archer AX53 covering five vulnerabilities: CVE-2026-30814, CVE-2026-30815, CVE-2026-30816, CVE-2026-30817, and CVE-2026-30818. The advisory coincided with the 2026-02-13 firmware release and expanded the known scope beyond the two CVEs already captured in the timeline.
TP-Link Archer AX53 v1.0 firmware version 1.7.1 Build 20260213 became the first version not affected by two OS command injection vulnerabilities in the router's OpenVPN and dnsmasq modules, indicating the issues were addressed by that release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
talosintelligence.com
Open sourcetalosintelligence.com
Open sourcetalosintelligence.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcetp-link.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.