TP-Link Archer AX53 Heap-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A heap-based buffer overflow vulnerability has been identified in the TP-Link Archer AX53 v1.0, specifically within the 'tmpserver' and 'tdpserver' modules. This vulnerability allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code by sending a specially crafted network packet that exceeds the maximum expected length. The issue arises from insufficient validation of packet lengths, field offsets, and the presence of excessive zero-length fields, which can be exploited to manipulate memory and execute unauthorized code.

Impact

Exploitation of this vulnerability can lead to a segmentation fault or arbitrary code execution on the affected device.

Remediation

Users are advised to update to the latest firmware version. The latest firmware for the Archer AX53 v1.0 can be downloaded from the TP-Link official website or the TP-Link Malaysia website.

Added: Feb 3, 2026, 7:41 PM
Updated: Feb 3, 2026, 7:41 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
3.1
remediation
7.7
relevance
2.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.