Impact
A stored Cross‑Site Scripting flaw exists in the web‑based management interface of TP‑Link Archer C5 routers running firmware 6.8. The bug arises encoding of user‑controlled input in a configuration field. An attacker who has administrative privileges can inject crafted HTML or JavaScript. The payload is stored persistently and executed whenever an administrator refreshes the affected page, allowing arbitrary code execution within the admin’s browser. This can enable session hijacking, unauthorized changes to router settings, and exposure of sensitive data.
Affected Systems
The vulnerability affects TP‑Link Archer C5 routers that ship with firmware version 6.8. The affected products are listed in the vendor’s support documentation and are delivered through service providers.
Risk and Exploitability
The CVSS score of 7 indicates a high severity, yet the EPSS score is less than 1% and the flaw is not listed in CISA’s KEV catalog. Exploitation requires an attacker to possess administrative credentials or to compromise an existing admin to inject the malicious payload. Once injected, any subsequent access by an administrator triggers the execution of the script, leading to session hijack or configuration tampering. Attackers cannot directly trigger the XSS without prior admin‑level access, limiting the immediate threat to environments where the router is managed locally or where the admin credentials are weak or shared.
OpenCVE Enrichment