Junglewise Threat Intelligence

CVE-2026-8699: TP-Link Archer C5 stored XSS in web management interface

CVE-2026-8699 · Severity: info · CVSS 7 · Published 2026-07-02

Vendors: TP-Link.

Executive brief

A security vulnerability exists in the web management interface of TP-Link Archer C5 v6.8 routers managed by Internet Service Providers (ISPs). An attacker with administrative access can plant malicious code that executes when another administrator views certain settings pages. This could allow the attacker to hijack sessions, steal sensitive configuration data, or modify device settings, potentially compromising the security of the local network.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the web-based management interface of TP-Link Archer C5 v6.8 routers due to insufficient server-side validation and lack of proper output encoding. An attacker with administrative privileges can inject crafted HTML or JavaScript payloads into specific user-controlled fields. These payloads are stored on the device and executed when an administrator navigates to the affected page. This vulnerability specifically affects ISP-managed firmware variants. Successful exploitation can lead to session hijacking and unauthorized modification of router configurations. TP-Link has provided updated firmware to ISPs for deployment.

Affected products

  • TP-Link Archer C5 v6.8 < 0.2.0 3.0.0 v6063.0 Build 260331 Rel.37416n

Timeline

  • 2026-07-02: disclosed
  • 2026-07-02: advisory

References