CVE-2026-30816: Arbitrary File Reading Vulnerability in OpenVPN Module in TP-Link AX53
An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30816?
CVE-2026-30816 is rated as a high severity vulnerability due to the potential for unauthorized file access.
How do I fix CVE-2026-30816?
To fix CVE-2026-30816, update the firmware of the TP-Link AX53 to the latest version available that addresses this vulnerability.
Who is affected by CVE-2026-30816?
The vulnerability CVE-2026-30816 affects users of the TP-Link AX53 version 1.0 running firmware versions prior to 1.7.1.
What type of vulnerability is CVE-2026-30816?
CVE-2026-30816 is an arbitrary file reading vulnerability affecting the OpenVPN module.
Can CVE-2026-30816 be exploited remotely?
CVE-2026-30816 requires authentication from an adjacent attacker to exploit the vulnerability.