Vulnerability Description
Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login. An adjacent attacker with the ability to intercept network traffic could potentially perform a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext administrator password, leading to unauthorized access and compromise of the device configuration. This issue affects Archer C7: through Build 20220715.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Archer C7 Firmware | - |
| Tp-Link | Archer C7 | 5.0 |
Related Weaknesses (CWE)
References
- https://www.tp-link.com/us/support/faq/3562/Not Applicable
FAQ
What is CVE-2026-5363?
CVE-2026-5363 is a vulnerability with a CVSS score of 8.8 (HIGH). Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RS...
How severe is CVE-2026-5363?
CVE-2026-5363 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-5363?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Archer C7 Firmware, Tp-Link Archer C7.