CVE-2026-1571
MEDIUMTP-Link Archer C60 v3 - XSS
Title source: llmDescription
User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbitrary JavaScript execution via a crafted URL. An attacker could run script in the device web UI context, potentially enabling credential theft, session hijacking, or unintended actions if a privileged user is targeted.
Scores
CVSS v3
6.1
EPSS
0.0001
EPSS Percentile
2.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (1)
tp-link/archer_c60_firmware
< 260206
Timeline
Published
Feb 11, 2026
Tracked Since
Feb 18, 2026