GHSA-28h6-3mx2-8gjg · Severity: high — An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an...
An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow the attacker to modify device configuration, access sensitive information, or further compromise system integrity. This issue affects AX53 v1.0: before 1.7.1 Build 20260213.
Conclusion & alert: CVE-2026-30818 is rated Moderate Risk (45.5/100): CVSS High severity, with low exploitation likelihood (EPSS 0.14%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-20 | 0.16% | 0.14% | -0.03% |
| 2 | 2026-04-29 | 0.14% | 0.16% | +0.02% |
| 3 | 2026-04-15 | — | 0.14% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.5 | 4.0 | HIGH |
|
— | — | f23511db-6c3e-4e32-a477-6aa17d310630 |
| 8.0 | 3.1 | HIGH |
|
2.1 | 5.9 | [email protected] |
GHSA-28h6-3mx2-8gjg · Severity: high — An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| tp-link | archer_ax53_firmware | < 1.7.1 | cpe:2.3:o:tp-link:archer_ax53_firmware:*:*:*:*:*:*:*:* |