Vulnerabilities & Exploits

Router Firmware Cluster Spreads Risk Beyond One Bug

This is not a single flaw. It is a cluster of separately patched bugs across TP-Link, Adobe, OpenVPN, and Norton VPN, and the AX53 set points to a broader firmware quality problem rather than an isolated miss. The Norton VPN case matters more because Talos saw it in use before a patch existed, so this is not just a theoretical disclosure.

Talos disclosed eight TP-Link Archer AX53 vulnerabilities, including CVE-2026-30814, a stack-based buffer overflow that can lead to arbitrary code execution, and several OpenVPN-related issues that can lead to command execution or file reading. It also disclosed one flaw each in Adobe Photoshop and Gen Digital Norton VPN; most issues were already patched by the vendors, except the Norton VPN issue, which had been observed in use before a fix was available.

For defenders, the practical risk is the router itself becoming a foothold into the local network, not just a broken edge device. The AX53 findings also suggest the firmware has multiple weak points in the same release, so this looks like a pattern in the code base, not one bad function.

1 source · May 19

CVEs in this update

8 CVEs

Across OpenVPN.

0 critical · 3 high · 2 medium · 0 low

0 in CISA KEV · 2 with EPSS above 1%

Highest severity: CVE-2025-58074 · 8.8 HIGH

Highest EPSS: CVE-2026-30815 · 1.6%

Timeline

Sources

Part of the PlainSec briefing for 2026-05-19

Every edition of this story: Router Firmware Cluster Spreads Risk Beyond One Bug

More from today