CVE-2026-0834
Unknown Unknown - Not Provided
Unauthenticated Command Execution in TP-Link TDDP Causes Device Reset

Publication date: 2026-01-21

Last updated on: 2026-04-28

Assigner: TPLink

Description
Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials.Β Attackers on the adjacent network can remotely trigger factory resets and reboots without credentials, causing configuration loss and interruption of device availability. This issue affects Archer C20 v6.0 < V6_251031, Archer C20 v5
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-21
Last Modified
2026-04-28
Generated
2026-05-27
AI Q&A
2026-01-21
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
tp-link archer_ax53_firmware 1.0
tp-link archer_c20_firmware 6.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a logic flaw in the TP-Link Archer C20 v6.0 and Archer AX53 v1.0 devices, specifically in the TDDP module. It allows attackers who are on an adjacent network to execute administrative commands such as factory reset and device reboot without needing any credentials. This means unauthorized users nearby can remotely trigger these commands, potentially disrupting the device's normal operation.


How can this vulnerability impact me? :

The vulnerability can impact you by allowing attackers on an adjacent network to remotely cause your device to reboot or perform a factory reset without authorization. This can lead to loss of your device's configuration settings and interruption of device availability, potentially causing network downtime or loss of connectivity.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, update the firmware of your TP-Link Archer C20 v6.0 and Archer AX53 v1.0 devices to the latest versions provided by TP-Link. Check the official TP-Link download pages for Archer AX53 and Archer C20 to obtain the latest firmware that addresses this issue. [1, 2]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart