6.8
/ 10
MEDIUM
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.
Basic Information
ID
CVE-2026-30817
Source
TPLink
Published
Apr 8, 2026 at 17:53
Modified
Apr 8, 2026 at 19:21
Affected Product
Vendor
TP-Link Systems Inc.
Product
AX53 v1.0
Affected Versions
TP-Link Systems Inc. AX53 v1.0 0