CVE-2026-5363: Use of weak cryptographic key in TP-Link Archer C7
Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login. An adjacent attacker with the ability to intercept network traffic could potentially perform a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext administrator password, leading to unauthorized access and compromise of the device configuration. This issue affects Archer C7: through Build 20220715.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5363?
CVE-2026-5363 has been classified as a medium severity vulnerability due to its potential exploitation for unauthorized access.
How do I fix CVE-2026-5363?
You can fix CVE-2026-5363 by updating your TP-Link Archer C7 v5 or v5.8 to the latest firmware version that addresses this vulnerability.
What does CVE-2026-5363 affect?
CVE-2026-5363 affects TP-Link Archer C7 v5 and v5.8 routers with specific firmware versions, particularly involving the uhttpd module.
What type of attacks can CVE-2026-5363 enable?
CVE-2026-5363 can enable attackers to exploit weak cryptographic keys for password recovery and potentially gain unauthorized access to the router.
Is my router vulnerable if I am using an older firmware version of TP-Link Archer C7?
Yes, if you are using an older firmware version of the TP-Link Archer C7 v5 or v5.8, you are vulnerable to CVE-2026-5363.