CVE-2026-8699 Details
Description
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insufficient server-side validation and lack of proper output encoding of user-controlled input in a certain field. An attacker with administrative privileges can inject crafted HTML or JS payloads into the affected field. The payload is stored and later executed when the affected page is rendered in an administrator's browser.Successful exploitation allows execution of arbitrary JavaScript in an admin's browser, potentially leading to session hijacking and unauthorized access to router configuration, possibly resulting in exposure of sensitive data and modification of device settings. The vulnerability affects ISP-managed firmware variants of the product. Remediation is coordinated through service providers.
A stored Cross-Site Scripting vulnerability has been identified in the web-based management interface of TP-Link Archer C5 routers running ISP-managed firmware versions prior to 0.2.0 3.0.0 v6063.0 Build 260331 Rel.37416n. This vulnerability arises from inadequate server-side validation and improper output encoding of user-controlled input, allowing an attacker with administrative privileges to inject malicious HTML or JavaScript payloads. These payloads are stored and executed when the affected page is viewed in an administrator's browser. Exploitation of this vulnerability could lead to the execution of arbitrary JavaScript in the admin's browser, potentially allowing session hijacking and unauthorized access to router configurations, with risks of exposing sensitive data and altering device settings.
For affected devices running ISP-managed firmware, the respective Internet Service Providers are handling remediation. TP-Link has provided updated firmware to ISPs in India, which is being deployed automatically to affected devices. Customers should contact their ISP for information on the update status. Devices purchased through retail channels with standard TP-Link firmware are not affected.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 2, 2026CISA-ADP
Assessed Jul 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/faq/5165/ | TPLink | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | TPLink |
Affected Products
| Product | Versions |
|---|---|
| TP-Link Archer C5 | < 0.2.0 3.0.0 v6063.0 Build 260331 Rel.37416n |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | CVE Modified | CISA-ADP |
| Jul 2, 2026 | New CVE Received | TPLink |
Volerion