{"api_version":"1","generated_at":"2026-04-23T02:24:47+00:00","cve":"CVE-2026-0834","urls":{"html":"https://cve.report/CVE-2026-0834","api":"https://cve.report/api/cve/CVE-2026-0834.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-0834","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-0834"},"summary":{"title":"Logic Vulnerability on TP-Link Archer C20 and Archer AX53","description":"Logic vulnerability in TP-Link Archer C20 v6.0 and Archer AX53 v1.0 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials. Attackers on the adjacent network can remotely trigger factory resets and reboots without credentials, causing configuration loss and interruption of device availability.This issue affects Archer C20 v6.0 < V6_251031, Archer C20 v5 <EU_V5_260317 or < US_V5_260419\n\n\nArcher AX53 v1.0 < \n\nV1_251215","state":"PUBLISHED","assigner":"TPLink","published_at":"2026-01-21 18:16:24","updated_at":"2026-04-22 22:16:30"},"problem_types":["CWE-290","CWE-290 CWE-290 Authentication Bypass by Spoofing"],"metrics":[{"version":"4.0","source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","score":"7.2","severity":"HIGH","vector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"7.2","severity":"HIGH","vector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":7.2,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"}},{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}}],"references":[{"url":"https://www.tp-link.com/en/support/download/archer-c20/v6/#Firmware","name":"https://www.tp-link.com/en/support/download/archer-c20/v6/#Firmware","refsource":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Product"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.tp-link.com/us/support/download/archer-c20/v5/#Firmware","name":"https://www.tp-link.com/us/support/download/archer-c20/v5/#Firmware","refsource":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.tp-link.com/en/support/download/archer-c20/v5/#Firmware","name":"https://www.tp-link.com/en/support/download/archer-c20/v5/#Firmware","refsource":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://mattg.systems/posts/cve-2026-0834/","name":"https://mattg.systems/posts/cve-2026-0834/","refsource":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Permissions Required"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.tp-link.com/us/support/faq/4905/","name":"https://www.tp-link.com/us/support/faq/4905/","refsource":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware","name":"https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware","refsource":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Product"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-0834","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0834","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"Archer C20 v6.0, Archer AX53 v1.0","version":"affected V6_251031 custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"Archer C20 v6.0, Archer AX53 v1.0","version":"affected V1_251215 custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"Archer C20 V5","version":"affected US_V5_260419 custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"Archer C20 V5","version":"affected EU_V5_260317 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Matt Graham (mattg.systems)","lang":"en"}],"nvd_cpes":[{"cve_year":"2026","cve_id":"834","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"tp-link","cpe5":"archer_ax53","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"834","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"tp-link","cpe5":"archer_ax53_firmware","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"834","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"tp-link","cpe5":"archer_c20","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"834","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"tp-link","cpe5":"archer_c20_firmware","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"834","cve":"CVE-2026-0834","epss":"0.000080000","percentile":"0.008100000","score_date":"2026-04-22","updated_at":"2026-04-23 00:03:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-0834","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-01-22T04:55:49.767529Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-02-26T14:44:34.299Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","modules":["tddp"],"product":"Archer C20 v6.0, Archer AX53 v1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"V6_251031","status":"affected","version":"0","versionType":"custom"},{"lessThan":"V1_251215","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","modules":["tddp"],"product":"Archer C20 V5","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"US_V5_260419","status":"affected","version":"0","versionType":"custom"},{"lessThan":"EU_V5_260317","status":"affected","version":"0","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Matt Graham (mattg.systems)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Logic vulnerability <span>in TP-Link Archer C20 v6.0 and Archer AX53 v1.0 (</span>TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials.&nbsp;Attackers on the adjacent network can remotely trigger factory resets and reboots without credentials, causing configuration loss and interruption of device availability.<p>This issue affects Archer C20 v6.0 &lt; V6_251031, Archer C20 v5 &lt;EU_V5_260317 or &lt;&nbsp;US_V5_260419<br>\n\nArcher AX53 v1.0 &lt; \n\nV1_251215<br></p>"}],"value":"Logic vulnerability in TP-Link Archer C20 v6.0 and Archer AX53 v1.0 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials. Attackers on the adjacent network can remotely trigger factory resets and reboots without credentials, causing configuration loss and interruption of device availability.This issue affects Archer C20 v6.0 < V6_251031, Archer C20 v5 <EU_V5_260317 or < US_V5_260419\n\n\nArcher AX53 v1.0 < \n\nV1_251215"}],"impacts":[{"capecId":"CAPEC-88","descriptions":[{"lang":"en","value":"CAPEC-88 OS Command Injection"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":7.2,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-290","description":"CWE-290 Authentication Bypass by Spoofing","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-04-22T21:30:37.012Z","orgId":"f23511db-6c3e-4e32-a477-6aa17d310630","shortName":"TPLink"},"references":[{"tags":["patch"],"url":"https://www.tp-link.com/en/support/download/archer-c20/v6/#Firmware"},{"tags":["patch"],"url":"https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware"},{"url":"https://mattg.systems/posts/cve-2026-0834/"},{"tags":["vendor-advisory"],"url":"https://www.tp-link.com/us/support/faq/4905/"},{"tags":["patch"],"url":"https://www.tp-link.com/us/support/download/archer-c20/v5/#Firmware"},{"tags":["patch"],"url":"https://www.tp-link.com/en/support/download/archer-c20/v5/#Firmware"}],"source":{"discovery":"UNKNOWN"},"title":"Logic Vulnerability on TP-Link Archer C20 and Archer AX53","x_generator":{"engine":"Vulnogram 0.5.0"}}},"cveMetadata":{"assignerOrgId":"f23511db-6c3e-4e32-a477-6aa17d310630","assignerShortName":"TPLink","cveId":"CVE-2026-0834","datePublished":"2026-01-21T17:14:55.179Z","dateReserved":"2026-01-09T21:48:53.385Z","dateUpdated":"2026-04-22T21:30:37.012Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-01-21 18:16:24","lastModifiedDate":"2026-04-22 22:16:30","problem_types":["CWE-290","CWE-290 CWE-290 Authentication Bypass by Spoofing"],"metrics":{"cvssMetricV40":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:archer_ax53_firmware:1.0:*:*:*:*:*:*:*","matchCriteriaId":"8C762E60-933C-4B61-84D1-0A6FE4D5E08E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:archer_ax53:-:*:*:*:*:*:*:*","matchCriteriaId":"394AAF99-8784-4872-8EED-A12B97C575E4"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:archer_c20_firmware:6.0:*:*:*:*:*:*:*","matchCriteriaId":"E36B6485-1C16-4FC9-B5ED-3B0D5FC9B16B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:archer_c20:-:*:*:*:*:*:*:*","matchCriteriaId":"4FFFAF05-D4CE-454A-B830-7899CAFC8ED0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"834","Ordinal":"1","Title":"Logic Vulnerability on TP-Link Archer C20 and Archer AX53","CVE":"CVE-2026-0834","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"834","Ordinal":"1","NoteData":"Logic vulnerability in TP-Link Archer C20 v6.0 and Archer AX53 v1.0 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials. Attackers on the adjacent network can remotely trigger factory resets and reboots without credentials, causing configuration loss and interruption of device availability.This issue affects Archer C20 v6.0 < V6_251031, Archer C20 v5 <EU_V5_260317 or < US_V5_260419\n\n\nArcher AX53 v1.0 < \n\nV1_251215","Type":"Description","Title":"Logic Vulnerability on TP-Link Archer C20 and Archer AX53"}]}}}