TP-Link Archer AX53 Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the TP-Link Archer AX53 V1 router. This issue arises in the 'mscd' debug functionality, where inadequate input validation allows authenticated attackers to redirect logs to arbitrary files and append unvalidated file contents to shell commands. Exploitation of this vulnerability could enable the execution of malicious commands, potentially leading to full control of the device.

Impact

Exploitation of this vulnerability allows authenticated attackers to inject and execute arbitrary commands on the device, potentially leading to full control over it.

Remediation

Users are advised to download and update to the latest firmware version. The latest firmware can be downloaded from the TP-Link official website for the Archer AX53 V1.

Added: Mar 20, 2026, 5:30 PM
Updated: Mar 20, 2026, 5:30 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.5
remediation
0.0
relevance
4.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.