CVE-2026-30814: Buffer Overflow Vulnerability in TP-Link AX53
A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a crash and could allow arbitrary code execution, enabling modification of device state, exposure of sensitive data, or further compromise of device integrity. This issue affects AX53 v1.0: before 1.7.1 Build 20260213.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30814?
CVE-2026-30814 is classified as a high-severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2026-30814?
To mitigate CVE-2026-30814, update the TP-Link Archer AX53 firmware to version 1.7.1 or later.
Who is affected by CVE-2026-30814?
CVE-2026-30814 affects TP-Link Archer AX53 devices running firmware versions prior to 1.7.1.
What kind of attack can be executed via CVE-2026-30814?
An authenticated adjacent attacker can exploit CVE-2026-30814 to create a specially crafted configuration file that triggers a buffer overflow.
Is CVE-2026-30814 a remote vulnerability?
No, CVE-2026-30814 requires an authenticated adjacent attacker, meaning the attacker must be on the same network.