CVE-2026-1571: TP-Link Archer c60 Firmware
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbitrary JavaScript execution via a crafted URL. An attacker could run script in the device web UI context, potentially enabling credential theft, session hijacking, or unintended actions if a privileged user is targeted.
Affected products
- TP-Link Archer c60 Firmware: before 260206 (fixed in 260206)
Published 2026-02-11. Last modified 2026-06-17.