Junglewise Threat Intelligence

CVE-2026-8697: TP-Link Archer C64 improper authentication rate-limiting in debug SSH

CVE-2026-8697 · Severity: info · CVSS 8.7 · Published 2026-05-28

Vendors: TP-Link.

Executive brief

A security vulnerability exists in the TP-Link Archer C64 router (v1) due to a debug SSH service that lacks proper login protections. An attacker on the same local network can repeatedly guess passwords without being locked out, eventually gaining full administrative control over the device. This could allow an unauthorized person to monitor internet traffic, change network settings, or disable the device entirely.

Technical details

A vulnerability in the debug SSH service of TP-Link Archer C64 v1 (CWE-288) stems from improper enforcement of authentication rate-limiting. The SSH service shares the same credentials as the web management interface but lacks the protective throttling mechanisms found in the web UI. An attacker with adjacent network access can perform an automated brute-force attack to identify valid administrative credentials. Successful exploitation grants full shell access and administrative control over the router. The issue is resolved in firmware version 1.15.0 Build 250729 Rel.63489n or later.

Affected products

  • TP-Link Archer C64 v1 (prior to firmware 1.15.0 Build 250729 Rel.63489n)

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory
  • 2026-05-28: patched

References