Vulnerabilities (CVE)

Filtered by vendor Tp-link Subscribe
Filtered by product Archer C60
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-1571 1 Tp-link 2 Archer C60, Archer C60 Firmware 2026-02-20 N/A 6.1 MEDIUM
User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbitrary JavaScript execution via a crafted URL. An attacker could run script in the device web UI context, potentially enabling credential theft, session hijacking, or unintended actions if a privileged user is targeted.