CVE-2026-1571

User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbitrary JavaScript execution via a crafted URL. An attacker could run script in the device web UI context, potentially enabling credential theft, session hijacking, or unintended actions if a privileged user is targeted.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:archer_c60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_c60:3.0:*:*:*:*:*:*:*

History

17 Jun 2026, 10:16

Type Values Removed Values Added
Summary
  • (es) La entrada controlada por el usuario se refleja en la salida HTML sin la codificación adecuada en TP-Link Archer C60 v3, permitiendo la ejecución arbitraria de JavaScript a través de una URL manipulada. Un atacante podría ejecutar scripts en el contexto de la interfaz de usuario web del dispositivo, lo que podría permitir el robo de credenciales, el secuestro de sesión o acciones no deseadas si un usuario privilegiado es el objetivo.

20 Feb 2026, 20:19

Type Values Removed Values Added
References () https://www.tp-link.com/en/support/download/archer-c60/#Firmware - () https://www.tp-link.com/en/support/download/archer-c60/#Firmware - Product
References () https://www.tp-link.com/us/support/faq/4961/ - () https://www.tp-link.com/us/support/faq/4961/ - Vendor Advisory
CPE cpe:2.3:o:tp-link:archer_c60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_c60:3.0:*:*:*:*:*:*:*
First Time Tp-link archer C60 Firmware
Tp-link
Tp-link archer C60
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

11 Feb 2026, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 01:15

Updated : 2026-06-17 10:16


NVD link : CVE-2026-1571

Mitre link : CVE-2026-1571

CVE.ORG link : CVE-2026-1571


JSON object : View

Products Affected

tp-link

  • archer_c60_firmware
  • archer_c60
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')