TP-Link Archer A7 Archer A7(US)V5210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on the router.
UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)V5200721 allows an authenticated admin user, with physical access and network access, to execute arbitrary code after plugging a crafted USB drive into the router.