CVE-2026-30814HIGH 8.0EPSS p33.3%

CVE-2026-30814CVE-2026-30814

Description

A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a crash and could allow arbitrary code execution, enabling modification of device state, exposure of sensitive data, or further compromise of device integrity. This issue affects AX53 v1.0: before 1.7.1 Build 20260213.

Scoring

CVSS 3.18.0 (HIGH)
VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS0.42% probability of exploitation · percentile 33.3% · 2026-06-18T12:00:27Z
Published2026-04-08
Last modified2026-05-07

Underlying weaknesses· 2

CWE-121CWE-787

References

  1. https://talosintelligence.com/vulnerability_reports/
  2. https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware
  3. https://www.tp-link.com/my/support/download/archer-ax53/v1/#Firmware
  4. https://www.tp-link.com/us/support/faq/5055/
  5. https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2302

2

TypeTargetConfidenceTier
WeaknessStack-based Buffer Overflowcwe-1210%live
WeaknessOut-of-bounds Writecwe-7870%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-62404
CVE
CVE-2025-58455
CVE
CVE-2025-59482
CVE
CVE-2025-58077
CVE
CVE-2025-61983
CVE
CVE-2025-61944
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.