Weak RSA-1024 password encryption enables recovery on TP-Link Archer C7

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-5363?

CVE-2026-5363 is a vulnerability classified as Inadequate Encryption Strength, affecting Archer C7 v5 and v5.8 (affected versions: ≤ Build 20220715). This vulnerability is rated Medium, with a CVSS score of 5.4. Current sources do not report this vulnerability as exploited.

Overview

Original source data

Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login. An adjacent attacker with the ability to intercept network traffic could potentially perform a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext administrator password, leading to unauthorized access and compromise of the device configuration. This issue affects Archer C7: through Build 20220715.

Affected products and scope

  • TP-Link Systems Inc. Archer C7 v5 and v5.8, component uhttpd: affected from version 0 through and including Build 20220715, according to the CNA's custom range. The default status outside the supplied affected declaration is unaffected.
  • The analyzed NVD configuration separately uses versionEndExcluding: 1.2.1 for the archer_c7_firmware product. The public record does not clearly map that firmware boundary to the CNA's Build 20220715 notation, so the two representations should not be assumed to be equivalent.
  • TP-Link's current US end-of-life list includes Archer C7 v5.0 and v5.8 with past EOS milestones. Devices in these hardware revisions should be checked as potentially unsupported.

Technical details

The flaw is in the web interface login flow associated with the uhttpd modules. The web interface encrypts the administrator password client-side with RSA-1024 before sending it to the router. An adjacent attacker able to intercept the traffic could collect the encrypted login data and attempt a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext password.

The high-level attack flow described by the record is:

  1. An administrator enters a password in the web interface.
  2. The client encrypts the password with RSA-1024 and sends the resulting data to the router.
  3. An adjacent attacker intercepts the traffic and attempts to recover the password from the weak RSA key.
  4. The recovered password may then be used for unauthorized access and compromise of the device configuration.

The record does not disclose how the key is generated, stored, or reused, what RSA padding is used, or whether each device has a unique key. Practical exploitability therefore depends on implementation details that have not been published and on the attacker's ability to intercept the relevant login traffic.

Exploitability

Exploitation requires an adjacent network position and the ability to intercept traffic for the administration login. The record indicates that prior authentication is not required and that no additional user interaction is required, but describes key recovery as high complexity. The supplied public_exploit field is false, and the record does not mark the issue as known exploited. CISA enrichment records exploitation as none within that assessment's scope; this does not establish that exploitation has not occurred in every environment. The CNA assessment includes proof-of-concept exploit maturity, but provides no PoC artifact, tool, or specific exploit sequence.

Technical impact

The directly confirmed outcome is recovery of the plaintext administrator password, leading to unauthorized access and compromise of the device configuration. This primarily affects the confidentiality of the credential and administrative control of the router. The NVD assessment models broader confidentiality, integrity, and availability consequences, but the CNA narrative does not establish a specific post-authentication action sequence. The record also does not establish whether a compromised device could be used to reach other systems.

Business impact

  • Credential exposure: The administrator password may be recovered if an attacker can intercept login traffic and defeat the weak RSA key.
  • Administrative compromise: A recovered password may provide unauthorized access to the device and permit configuration changes.
  • Operational risk: Unauthorized configuration changes could affect network operation, but the record does not identify specific changes or a confirmed incident.
  • Evidence limit: The supplied evidence names no organization, victim, campaign, or specific breach.

Remediation

  1. Inventory the exact hardware revision and firmware/build. The CNA identifies Archer C7 v5 and v5.8 through and including Build 20220715 as affected.
  2. Apply firmware supported by TP-Link for the exact hardware revision and deployment region. The normalized record marks a patch as available, while the analyzed NVD configuration uses versionEndExcluding: 1.2.1 for archer_c7_firmware; however, no vendor solution text confirms how 1.2.1 maps to Build 20220715, so confirm the precise release with TP-Link before deployment.
  3. If TP-Link does not provide supported firmware for the specific device, replace the router. TP-Link's end-of-life list includes the relevant hardware revisions.
  4. Until upgrade or replacement, restrict the administration interface to trusted local networks and avoid administrative logins over networks where an adjacent attacker could intercept traffic. This is a temporary precaution, not a vendor-confirmed fix.

Detection

  1. Inventory TP-Link Archer C7 devices, identify the exact hardware revision and installed firmware/build, and compare them with the affected scope in affected_summary.
  2. In an authorized test environment, inspect the web login flow and traffic between the client and router to verify use of client-side RSA-1024 encryption. Do not collect or retain real passwords during testing.
  3. Check the hardware revision's support and end-of-life status against TP-Link sources, because the affected variants appear in TP-Link's US end-of-life list.
  4. Review administrative access records and configuration-change records for unexpected activity as a precaution. The record provides no specific IOC or log event, and the absence of suspicious logs does not prove that a device is safe.
Sources (9)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan