CVE-2026-8697 Details
Description
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web interface. This enables an attacker to brute-force valid credentials via SSH. Successful exploitation could allow an attacker with adjacent network access to obtain administrative credentials through unrestricted authentication attempts and subsequently gain full administrative access to the device, impacting system confidentiality, integrity, and availability.
A vulnerability exists in the TP-Link Archer C64 V1 due to improper authentication rate-limiting on a debug SSH service. This flaw allows unlimited authentication attempts using the same credentials as the web interface, enabling brute-force attacks on valid SSH credentials. Exploitation of this vulnerability could lead to an attacker with adjacent network access obtaining administrative credentials, thereby gaining full administrative access to the device.
Users are advised to update their devices to the latest firmware version 1.15.0 Build 250729, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/archer-c64/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5105/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link archer c64 firmware | 1.15.0 |
CPE
Remediation
| |
| tp-link archer c64 | 1.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| May 28, 2026 | New CVE Received | TPLink |