CVE-2026-10562 Details
Description
An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of user-supplied URL input within the web interface. An unauthenticated attacker can craft URLs containing URL-encoded path traversal sequences. When processed by the embedded web server, these inputs may cause the device to respond with HTTP 3xx redirects to attacker-controlled external domains. This issue affects Archer AX20 V2.0: through 2.1.9 Build 20230829.
A vulnerability allowing unauthenticated URL redirection has been identified in the TP-Link Archer AX20 V2. This issue arises from inadequate validation of user-supplied URL input in the web interface. An attacker can exploit this vulnerability by crafting URLs with URL-encoded path traversal sequences. When these URLs are processed by the device's embedded web server, the device may redirect to external domains controlled by the attacker. This vulnerability affects Archer AX20 V2.0, through 2.1.9 Build 20230829.
Users are advised to update their devices to the latest firmware version V2_260527, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/archer-ax20/v2/#Firmware | TPLink | ProductVendor |
| https://www.tp-link.com/en/support/faq/5156/ | TPLink | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | TPLink |
Affected Products
| Product | Versions |
|---|---|
| TP-Link Archer AX20 | >= 2.0, <= 2.1.9 Build 20230829 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | TPLink |
Volerion