CVE-2026-10562: Unauthenticated Open Redirect Vulnerability on TP-Link Archer AX20 Web Interface
An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of user-supplied URL input within the web interface. An unauthenticated attacker can craft URLs containing URL-encoded path traversal sequences.
When processed by the embedded web server, these inputs may cause the device to respond with HTTP 3xx redirects to attacker-controlled external domains.
This issue affects Archer AX20 V2.0: through 2.1.9 Build 20230829.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10562?
CVE-2026-10562 has a medium severity rating of 5.9 on the CVSS scale.
How do I fix CVE-2026-10562?
To mitigate CVE-2026-10562, it is important to upgrade the TP-Link Archer AX20 firmware to the latest version provided by TP-Link.
What type of vulnerability is CVE-2026-10562?
CVE-2026-10562 is classified as an unauthenticated open redirect vulnerability.
What can an attacker do with CVE-2026-10562?
An attacker can exploit CVE-2026-10562 to craft malicious URLs that redirect users to unintended locations.
Which devices are affected by CVE-2026-10562?
CVE-2026-10562 affects the TP-Link Archer AX20 V2 web interface.