CVE-2026-0834
Unknown
Unknown - Not Provided
Unauthenticated Command Execution in TP-Link TDDP Causes Device Reset
Publication date: 2026-01-21
Last updated on: 2026-04-28
Assigner: TPLink
Description
Description
Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials. Attackers on the adjacent network can remotely trigger factory resets and reboots without credentials, causing configuration loss and interruption of device availability.
This issue affects Archer C20 v6.0 < V6_251031, Archer C20 v5
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tp-link | archer_ax53_firmware | 1.0 |
| tp-link | archer_c20_firmware | 6.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-290 | This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks. |
Attack-Flow Graph
EPSS Chart
Did you find what you were looking for?
Thank you for your feedback!
Your input helps us improve and create a better experience for you.
We appreciate your time!