GHSA-57xx-hp7r-53h8 · Severity: high — An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an...
An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification of configuration files, disclosure of sensitive information, or further compromise of device integrity. This issue affects AX53 v1.0: before 1.7.1 Build 20260213.
Conclusion & alert: CVE-2026-30815 is rated Moderate Risk (46.2/100): CVSS High severity, with low exploitation likelihood (EPSS 0.15%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-20 | 0.16% | 0.15% | -0.01% |
| 2 | 2026-04-15 | 0.45% | 0.16% | -0.29% |
| 3 | 2026-04-14 | — | 0.45% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.5 | 4.0 | HIGH |
|
— | — | f23511db-6c3e-4e32-a477-6aa17d310630 |
| 8.0 | 3.1 | HIGH |
|
2.1 | 5.9 | [email protected] |
GHSA-57xx-hp7r-53h8 · Severity: high — An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| tp-link | archer_ax53_firmware | < 1.7.1 | cpe:2.3:o:tp-link:archer_ax53_firmware:*:*:*:*:*:*:*:* |