CVE-2026-0834Disclosure(tp-link / archer_ax53)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tp-link archer_ax53 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials. Attackers on the adjacent network can remotely trigger factory resets and reboots without credentials, causing configuration loss and interruption of device availability. This issue affects Archer C20 v6.0 < V6_251031, Archer C20 v5 <EU_V5_260317 or < US_V5_260419 Archer AX53 v1.0 < V1_251215 TL-WR841N v13 < 0.9.1 Build 20231120 Rel.62366

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • archer_ax53
  • archer_ax53_firmware
  • archer_c20
  • archer_c20_firmware

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-02); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
archer_ax53archer_ax53_firmwarearcher_c20archer_c20_firmware

3 versions affected across 4 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-02: 1Mentions · 2026-02-10: 1Patch / Workaround · 2026-02-10: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-10: 102-0202-10
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-021
Disclosure1
2026-02-101
Patch1
Full discourse2 posts
  • Grok@grok
    Patch

    En 2026, se han reportado múltiples vulnerabilidades por defecto en routers caseros, como credenciales predeterminadas en Four-Faith (afectando >15.000 dispositivos), CVE-2026-1623 en Totolink A7000R, CVE-2026-0834 en TP-Link Archer, y fallos en NETGEAR Orbi y chipsets Broadcom. No hay un conteo exacto fijo, ya que surgen continuamente. Recomiendo actualizar firmware, cambiar contraseñas default y usar firewalls fuertes para minimizar riesgos.

    Post summary

    Se han detectado vulnerabilidades con credenciales por defecto en varios routers caseros, afectando a miles de dispositivos; los usuarios deben actualizar el firmware, cambiar las contraseñas predeterminadas y activar firewalls para reducir el riesgo.

    0000052
    8.1M followersView on X
  • Matt Graham@mattgsys
    Disclosure

    First blog post: TP-Link Device Debug Protocol (TDDP) Authentication Bypass (CVE-2026-0834) https://mattg.systems/posts/cve-2026-0834/

    Post summary

    A blog post announces the discovery of an authentication bypass flaw in TP‑Link's Device Debug Protocol (CVE‑2026‑0834).

    0000061
    2 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linkarcher_ax53---
OStp-linkarcher_ax53_firmware1.0--
HWtp-linkarcher_c20---
OStp-linkarcher_c20_firmware6.0--

Explore more