CVE-2026-5363
Undergoing Analysis
Undergoing Analysis - In Progress
Weak RSA-1024 Encryption in TP-Link Archer C7 Enables Password Recovery
Publication date: 2026-04-16
Last updated on: 2026-05-22
Assigner: TPLink
Description
Description
Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation.Β The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login.Β
An adjacent attacker with the ability to intercept network traffic could potentially perform a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext administrator password, leading to unauthorized access and compromise of the device configuration.Β Β This issue affects Archer C7: through Build 20220715.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tp-link | archer_c7_firmware | to 1.2.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-326 | The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required. |