Successful exploitation could allow an attacker with adjacent network access to obtain administrative credentials through unrestricted authentication attempts and subsequently gain full administrative access to the device, impacting system confidentiality, integrity, and availability.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link archer C64 Firmware
|
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:h:tp-link:archer_c64:1.0:*:*:*:*:*:*:* cpe:2.3:o:tp-link:archer_c64_firmware:1.15.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tp-link archer C64 Firmware
|
|
| Metrics |
cvssV3_1
|
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link archer C64 |
|
| Vendors & Products |
Tp-link
Tp-link archer C64 |
Thu, 28 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web interface. This enables an attacker to brute-force valid credentials via SSH. Successful exploitation could allow an attacker with adjacent network access to obtain administrative credentials through unrestricted authentication attempts and subsequently gain full administrative access to the device, impacting system confidentiality, integrity, and availability. | |
| Title | Improper Authentication Rate Limiting on TP-Link's Archer C64 | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-05-29T03:55:51.604Z
Reserved: 2026-05-15T16:35:09.352Z
Link: CVE-2026-8697
Updated: 2026-05-28T19:26:02.748Z
Status : Analyzed
Published: 2026-05-28T17:16:33.657
Modified: 2026-06-03T18:14:26.590
Link: CVE-2026-8697
No data.
OpenCVE Enrichment
Updated: 2026-06-03T19:30:36Z