CVE-2026-30817: exploitation status and patch state

CVE-2026-30817 · CVSS 5.7 MEDIUM · EPSS <1%

An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.

Is CVE-2026-30817 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2026-30817

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-13.