CVE-2026-30815
An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification of configuration files, disclosure of sensitive information, or further compromise of device integrity.
This issue affects AX53 v1.0: before 1.7.1 Build 20260213.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.18%
- Percentil entre todas las CVEs puntuadas: 82
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement75 % - Impacto principal
T1059Command and Scripting Interpreterexecution85 % - Impacto secundario
T1005Data from Local Systemcollection65 % - Impacto secundario
T1565.001Stored Data Manipulationimpact70 %
AV:A (red adyacente) con PR:H (privilegios altos) requiere T1210. CWE-78 (command injection) y texto explícito de 'execute system commands' justifican T1059 como impacto primario. Modificación de configuración (T1565.001) y acceso a información sensible (T1005) como secundarios.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-78
Referencias
- https://talosintelligence.com/vulnerability_reports/
- https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware
- https://www.tp-link.com/my/support/download/archer-ax53/v1/#Firmware
- https://www.tp-link.com/us/support/faq/5055/
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2303
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2307
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2308
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2309
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-30815",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-30815",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-04-08T00:00:00+00:00"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.1
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.5,
"Automatable": "NOT_DEFINED",
"attackVector": "ADJACENT",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "HIGH",
"subIntegrityImpact": "LOW",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"affectedData": [
{
"vendor": "TP-Link Systems Inc.",
"modules": [
"openvpn"
],
"product": "AX53 v1.0",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.7.1 Build 20260213",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-04-08T19:25:20.320",
"references": [
{
"url": "https://talosintelligence.com/vulnerability_reports/",
"tags": [
"Third Party Advisory"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/my/support/download/archer-ax53/v1/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/faq/5055/",
"tags": [
"Vendor Advisory"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2303",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2307",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2308",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2309",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An OS command injection vulnerability in the OpenVPN module\nof TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification of configuration files, disclosure of sensitive information, or further compromise of device integrity.\n\nThis issue affects AX53 v1.0: before 1.7.1 Build 20260213."
},
{
"lang": "es",
"value": "Una vulnerabilidad de inyección de comandos del sistema operativo en el módulo OpenVPN de TP-Link Archer AX53 v1.0 permite a un atacante adyacente autenticado ejecutar comandos del sistema cuando se procesa un archivo de configuración especialmente diseñado debido a una validación de entrada insuficiente. La explotación exitosa puede permitir la modificación de archivos de configuración, la divulgación de información sensible o un mayor compromiso de la integridad del dispositivo.\n\nEste problema afecta a AX53 v1.0: anterior a 1.7.1 Build 20260213."
}
],
"lastModified": "2026-07-25T11:10:00.100",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:archer_ax53_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B096B7BB-7693-4C45-B5F7-8FD6E4969DCE",
"versionEndExcluding": "1.7.1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:archer_ax53:1.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5F3EA1D9-EB47-4785-9CF0-F2B51945917D"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "f23511db-6c3e-4e32-a477-6aa17d310630"
}