5.3
/ 10
MEDIUM
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Description
Logic vulnerability in TP-Link Archer C20 v6.0 and Archer AX53 v1.0 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials.ย Attackers on the adjacent network can remotely trigger factory resets and reboots without credentials, causing configuration loss and interruption of device availability.This issue affects Archer C20 v6.0 < V6_251031.
Archer AX53 v1.0 <
V1_251215
Archer AX53 v1.0 <
V1_251215
Basic Information
ID
CVE-2026-0834
Source
TPLink
Published
Jan 21, 2026 at 17:14
Modified
Jan 21, 2026 at 18:01
Affected Product
Vendor
TP-Link Systems Inc.
Product
Archer C20 v6.0, Archer AX53 v1.0
Affected Versions
TP-Link Systems Inc. Archer C20 v6.0, Archer AX53 v1.0 0
TP-Link Systems Inc. Archer C20 v6.0, Archer AX53 v1.0 0
TP-Link Systems Inc. Archer C20 v6.0, Archer AX53 v1.0 0