CVE-2026-30818 is an OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 routers. The flaw stems from insufficient input validation when processing configuration files, allowing authenticated adjacent attackers to execute arbitrary code and potentially modify device configurations, access sensitive information, or compromise system integrity. The vulnerability affects Archer AX53 v1.0 devices before firmware version 1.7.1 Build 20260213. The vulnerability carries a CVSS score of 8.0 (HIGH) with an adjacent network attack vector requiring low complexity and low-level authentication privileges. The attack requires no user interaction and can result in high-impact compromise across confidentiality, integrity, and availability. With an EPSS score of 0.0014, the vulnerability represents relatively lower exploitation probability compared to the broader CVE population. There is currently no evidence of active exploitation or public exploit code availability. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog, and community attention remains minimal. Organizations should prioritize patching to firmware version 1.7.1 Build 20260213 or later, particularly if their devices operate in environments accessible to adjacent authenticated users.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.1CPE matchmatch criteria | cpe:2.3:o:tp-link:archer_ax53_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.