Description

Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login.  An adjacent attacker with the ability to intercept network traffic could potentially perform a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext administrator password, leading to unauthorized access and compromise of the device configuration.  This issue affects Archer C7: through Build 20220715.

INFO

Published Date :

2026-04-15T23:45:54.271Z

Last Modified :

2026-04-16T23:10:46.170Z

Source :

TPLink
AFFECTED PRODUCTS

The following products are affected by CVE-2026-5363 vulnerability.

Vendors Products
Tp-link
  • Archer C7
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-5363.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability