Archer Ax53 Firmware
Vendor:
First CVE: Jan 21, 2026 · Active for under a year
18
Total CVEs
More Total CVEs than 93% of tracked products
18.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 69% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Archer Ax53 Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2026
6 months ago
Most Recent CVE
Apr 8, 2026
109 days ago
CVE Severity & Scoring
Archer Ax53 Firmware18 CVEs
11%
78%
11%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (16.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network15 (83.3%)
Attack Complexity
Low17 (94.4%)
High1 (5.6%)
Unknown0 (0.0%)
User Interaction
None18 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low14 (77.8%)
High0 (0.0%)
None4 (22.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-15608CRITICAL This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a s | Mar 20, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-15607CRITICAL A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbitrary files and concatenation of | Mar 20, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-30818HIGH An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted | Apr 8, 2026 | 8.0 | 30 | NO | NO |
CVE-2026-30815HIGH An OS command injection vulnerability in the OpenVPN module
of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafte | Apr 8, 2026 | 8.0 | 30 | NO | NO |
CVE-2026-30814HIGH A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute | Apr 8, 2026 | 8.0 | 28 | NO | NO |
CVE-2026-0834HIGH Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands inc | Jan 21, 2026 | 8.8 | 28 | NO | NO |
CVE-2025-62673HIGH Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary co | Feb 3, 2026 | 8.0 | 26 | NO | NO |
CVE-2025-62501HIGH SSH Hostkey misconfiguration vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows attackers to obtain device credentials through a specially crafted man‑in‑the‑midd | Feb 3, 2026 | 8.1 | 25 | NO | NO |
CVE-2025-62405HIGH Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execut | Feb 3, 2026 | 8.0 | 25 | NO | NO |
CVE-2025-62404HIGH Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execut | Feb 3, 2026 | 8.0 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Archer Ax53 Firmware
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0 | 13 | 8.3 | 0.6% | 0 | 0 |