@BuddieMac,
The CVEs you linked appear to be specifically related to specific hardware versions from Japan with the (JP) identifier. As the devices are non-US it is not something we have information for, however, of the models that I did take a look at, they were all updated to a version outside the bounds of the CVE. If you want to confirm, make sure you are navigating the firmware pages from the correct region(/jp/), and verifying the hardware versions reported in the CVEs.
As for updates, while the Archer AX3000 has not received an update in a while, it is still well supported with many of the latest features. If there is a specific feature missing, we would be more than happy to field the request to the teams.
The AX3000 does not currently appear on our End of Life List, so it should still be eligible for updates: TP-Link End of Life Products.
As for updates regarding CVEs, you can find a list of our security advisories, along with the process for how we handle these reports here: TP-Link - Security Advisory