Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-8699 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insufficient server-side validation and lack of proper output encoding of user-controlled input in a certain field.  An attacker with administrative privileges can inject crafted HTML or JS payloads into the affected field. The payload is stored and later executed when the affected page is rendered in an administrator's browser.Successful exploitation allows execution of arbitrary JavaScript in an admin's browser, potentially leading to session hijacking and unauthorized access to router configuration, possibly resulting in exposure of sensitive data and modification of device settings. The vulnerability affects ISP-managed firmware variants of the product. Remediation is coordinated through service providers.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://www.tp-link.com/en/support/faq/5165/ TPLinkAdvisoryRemedyVendor

Weakness Enumeration

CWE-IDCWE NameSource
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')TPLink

Affected Products

ProductVersions
TP-Link Archer C5
< 0.2.0 3.0.0 v6063.0 Build 260331 Rel.37416n

CPE

  • cpe:2.3:h:tp-link:archer_c5:*:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:archer_c5_firmware:*:*:*:*:*:*:*:*

Remediation

  • Workaround:low effort

    Contact your Internet Service Provider (ISP) for confirmation of update status or to inquire about the deployment of the fixed firmware.

Change History

2 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-8699
NVD Published Date:
Jul 2, 2026
NVD Last Modified:
Jul 2, 2026
Source:
TPLink
CVE-2026-8699 Details - Not Deferred