CVE-2026-8697Tp-link · Archer_c64_firmware
Vulnerability data via NVD (ingested)
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web interface. This enables an attacker to brute-force valid credentials via SSH. Successful exploitation could allow an attacker with adjacent network access to obtain administrative credentials through unrestricted authentication attempts and subsequently gain full administrative access to the device, impacting system confidentiality, integrity, and availability.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-8697os:"Archer C64 Firmware"More intel sources (5)
vuln:CVE-2026-8697vulnerabilities.cve_id: CVE-2026-8697CVE-2026-8697CVE-2026-8697"CVE-2026-8697" exploit -site:nvd.nist.gov