CVE-2016-10719: TP-Link Archer CR700 Firmware
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
TP-Link Archer CR-700 1.0.6 devices have an XSS vulnerability that can be introduced into the admin account through a DHCP request, allowing the attacker to steal the cookie information, which contains the base64 encoded username and password.
Affected products
- TP-Link Archer CR700 Firmware: version 1.0.6 only
Published 2019-05-15. Last modified 2026-06-17.