CVE-2026-5363
Last modified
CVE-2026-5363 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login. An adjacent attacker with the ability to intercept network traffic could potentially perform a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext administrator password, leading to unauthorized access and compromise of the device configuration. This issue affects Archer C7: through Build 20220715.. EPSS estimates a 0.09% chance of exploitation in the next 30 days.
Description
Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login. An adjacent attacker with the ability to intercept network traffic could potentially perform a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext administrator password, leading to unauthorized access and compromise of the device configuration. This issue affects Archer C7: through Build 20220715.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Archer C7 Firmware | < 1.2.1 |
References
- https://www.tp-link.com/us/support/faq/3562/Not Applicable
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-5363?
How severe is CVE-2026-5363?
How do I fix CVE-2026-5363?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-53624Fiber is an Express inspired web framework written in Go. Pr…4.8
- CVE-2026-53625GLPI is a free asset and IT management software package. Fro…7.5
- CVE-2026-53626GLPI is a free asset and IT management software package. Fro…7.1
- CVE-2026-53627GLPI is a free asset and IT management software package. Fro…6
- CVE-2026-53628GLPI is a free asset and IT management software package. Fro…5.9
- CVE-2026-53629GLPI is a free asset and IT management software package. Fro…7.1
- CVE-2026-53632launch-editor allows users to open files with line numbers i…5.5
- CVE-2026-53633Vitest is a testing framework powered by Vite. From 3.0.0 un…9.8
- CVE-2026-53634Sharp is a content management framework built for Laravel as…4.3
- CVE-2026-53635Open edX Platform enables the authoring and delivery of onli…7.6
- CVE-2026-53636Open edX Platform enables the authoring and delivery of onli…4.7
- CVE-2026-53637Sylius is an Open Source eCommerce Framework on Symfony. Ver…6.5
Are you affected by CVE-2026-5363?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
