Executive brief
A security vulnerability has been identified in the TP-Link Archer AX20 V2 router's web management interface. An attacker can create a malicious link that, when clicked by a user, redirects them from the legitimate router settings page to a fraudulent or harmful website. This type of attack is often used in phishing campaigns to steal login credentials or distribute malware by tricking users into believing they are still on a trusted device page.
Technical details
An unauthenticated URL redirection vulnerability (Open Redirect) exists in the TP-Link Archer AX20 V2 web interface due to improper validation of user-supplied URL input. The vulnerability is triggered when the embedded web server processes URLs containing URL-encoded path traversal sequences. An attacker can exploit this by crafting a malicious link that, when visited by an authenticated or unauthenticated user, causes the device to issue an HTTP 3xx redirect to an arbitrary external domain. This issue is fixed in firmware version V2_260527.
Affected products
- TP-Link Systems Inc. Archer AX20 V2.0 through 2.1.9 Build 20230829
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory
- 2026-06-30: patched: Firmware version V2_260527 released