Tp Link · Archer C64 · CVE-2026-8697
**Name of the Vulnerable Software and Affected Versions**
Archer C64 v1
**Description**
Improper enforcement of authentication rate-limiting on a debug SSH service allows unlimited authentication attempts. Because the SSH service uses the same credentials as the web interface, an attacker with adjacent network access can brute-force valid credentials to gain full administrative access to the device, impacting system confidentiality, integrity, and availability.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.