A logic vulnerability in the TP-Link Device Debug Protocol (TDDP) module affecting TP-Link Archer C20 v6.0 and Archer AX53 v1.0 allows an unauthenticated attacker on an adjacent network to invoke administrative commands without providing credentials. Reported reachable actions include factory reset and device reboot, enabling an attacker to remotely disrupt device operation and erase configuration. Affected versions include Archer C20 v6.0 prior to V6_251031 and Archer AX53 v1.0 prior to V1_251215.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small Python proof-of-concept exploit for CVE-2026-0834 affecting TP-Link's TDDP (TP-Link Device Debug Protocol) service. Structure: (1) README.md describing the vulnerability and warning that the PoC will factory reset and reboot the device; (2) cve-2026-0834.py, a standalone script. Exploit purpose/capabilities: The script crafts TDDPv2 UDP packets with pkt_length set to 0, matching the described vulnerable condition where DES decryption/authentication is skipped due to short-circuit evaluation. It then appends extra bytes beyond the 28-byte header so the target interprets them as command data. The PoC specifically issues two administrative commands without credentials: factory reset (command byte 0x49) and reboot (0x4A). It computes and inserts an MD5 digest over the 28-byte header (with the digest field zeroed during calculation) and sends the packet to the target, printing any response. Targeting/assumptions: Default target is 192.168.0.1 on UDP port 1040 (TDDP). The script binds locally to UDP source port 54321. It is tested against TP-Link Archer C20 V6 firmware 0.9.1 Build 4.19/4.20; README notes offsets/structures may differ across models/firmware and that TDDP may not be enabled by default on all devices. Operational notes: This is not a scanner/detector; it performs destructive actions (factory reset) and then reboots the device, making it an operational PoC with a hardcoded payload rather than a configurable framework module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.