Security readout for executives and security teams
Plain-English summary
This issue affects TP-Link Archer A7 v5 firmware Archer A7(US)_V5_200721. A malicious authenticated administrator with both network and physical access could use a crafted USB drive to make the router execute arbitrary code. The business risk is concentrated where these routers are physically accessible or administered by untrusted parties.
Executive priority
Treat this as a targeted infrastructure risk, not a broad internet worm risk. Prioritize environments where routers are physically accessible, shared, remotely administered by third parties, or protect sensitive network segments.
Technical view
The CVE describes UNIX symbolic link following in the TP-Link Archer A7 v5 firmware build Archer A7(US)_V5_200721. Exploitation requires an authenticated admin user, network access, physical access, and insertion of a crafted USB drive. Successful exploitation may lead to arbitrary code execution on the router.
Likely exposure
Exposure appears limited to TP-Link Archer A7 v5 devices running firmware Archer A7(US)_V5_200721. The source bundle does not identify other products, versions, CPEs, CVSS scoring, or affected deployment modes.
Exploitation context
CISA KEV is false in the provided bundle, and no cited source states active exploitation. The required conditions are high-friction: administrator authentication, network access, physical access, and a crafted USB device.
Researcher notes
Evidence is sparse. The bundle names symlink following and arbitrary code execution but does not provide CVSS, CWE, patch details, or broader affected-version ranges. Avoid extrapolating beyond Archer A7 v5 firmware Archer A7(US)_V5_200721.
Mitigation direction
- Inventory TP-Link Archer A7 v5 routers and record exact firmware versions.
- Check TP-Link and Tenable guidance for any fixed firmware or vendor workaround.
- Restrict router administration to trusted users and management networks.
- Prevent untrusted USB devices from being connected to affected routers.
- Replace or isolate affected routers if vendor guidance is unavailable.
Validation and detection
- Confirm whether any device runs Archer A7(US)_V5_200721 firmware.
- Verify admin access is limited to authorized administrators only.
- Review physical access controls around router USB ports.
- Check whether vendor guidance names a fixed firmware version.
- Document exceptions where replacement or isolation is chosen.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Execution behavior lookup
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2020-5795 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.tenable.com/security/research/tra-2020-60CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
