TP-Link Archer C20 V6.0 and AX53 V1.0 TDDP Authentication Bypass Vulnerability Allowing Unauthenticated Administrative Command Execution

Vulnerability

A logic vulnerability has been identified in the TP-Link Archer C20 V6.0 and Archer AX53 V1.0 routers, specifically within the TP-Link Device Debug Protocol (TDDP) module. This vulnerability allows unauthenticated adjacent attackers to execute administrative commands, such as factory resets and device reboots, without the need for credentials. The issue arises from an implementation flaw in the TDDP service, which is enabled by default on these devices. Attackers on the adjacent network can exploit this vulnerability to cause configuration loss and disrupt device availability.

Impact

Exploitation of this vulnerability allows for unauthorized execution of administrative commands, including factory resets and reboots, on the affected devices. This could lead to a complete loss of configuration and availability.

Reproduction

The vulnerability can be reproduced by sending a specially crafted TDDP packet with a 'pktLength' value of 0. This bypasses the DES encryption that is normally required for authentication. After the packet is received, the TDDP command handlers interpret the data as valid commands. By placing specific bytes at the correct offsets in the packet, it is possible to trigger administrative functions such as resetting the device or rebooting it.

Remediation

TP-Link has released firmware updates to address this vulnerability. Users of the Archer C20 V6.0 should update to version V6_241231, and users of the Archer AX53 V1.0 should update to version 1.2.2 Build 20230627. After updating, verify that TDDP is no longer active and block UDP port 1040 at the network level.

Added: Jan 21, 2026, 6:46 PM
Updated: Jan 21, 2026, 8:29 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
5.0
exploitability
5.8
remediation
8.3
relevance
2.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.