CVE-2026-30817: Arbitrary File Reading Vulnerability in dnsmasq Module in TP-Link AX53
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30817?
CVE-2026-30817 is classified as a moderate severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2026-30817?
To fix CVE-2026-30817, update the TP-Link AX53 firmware to version 1.7.1 or later.
Who is affected by CVE-2026-30817?
CVE-2026-30817 affects TP-Link AX53 devices running firmware versions prior to 1.7.1.
What type of attack can exploit CVE-2026-30817?
An authenticated adjacent attacker can exploit CVE-2026-30817 to read arbitrary files via a malicious OpenVPN configuration.
What should I do if my TP-Link AX53 is vulnerable to CVE-2026-30817?
If your TP-Link AX53 is vulnerable to CVE-2026-30817, it is crucial to apply the latest firmware update immediately.