CVE-2026-8697 affects TP-Link Archer C64 v1. The vulnerability is caused by improper enforcement of authentication rate-limiting on a debug SSH service exposed on the device. According to the provided content, this SSH service permits unlimited authentication attempts and authenticates with the same credentials used by the device’s web management interface. As a result, an attacker on an adjacent network can repeatedly attempt SSH logins until valid credentials are guessed or brute-forced. Once valid credentials are obtained, the attacker can authenticate to the device with administrative privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept for CVE-2026-8697 affecting TP-Link Archer C64 routers. The repo contains one executable code file, `poc.py`, plus duplicated documentation in `README.md` and `index.md`, and a license file. The exploit is not part of a larger framework. The core exploit logic in `poc.py` uses Python with `pexpect` to spawn the local `ssh` client and repeatedly attempt password authentication against `root@192.168.0.1` over TCP/22. It explicitly enables deprecated SSH algorithms (`diffie-hellman-group1-sha1`, `ssh-dss`) to interoperate with the router's legacy debug SSH service. The script disables host key checking and writes known-hosts data to `/dev/null`, then iterates through either a user-supplied password list or a default list of integers 0-99. It interprets server responses to distinguish failed attempts from the characteristic connection close that occurs after a correct password, thereby using the SSH service as an authentication oracle. The exploit's capability is credential brute forcing, not remote code execution. It does not obtain a shell or execute commands on the router. Its practical impact is recovery of the router's admin password, which can then be used to access the primary web management interface and gain full administrative control. The README explains that the vulnerable condition is a residual SSH service sharing credentials with the web UI but lacking rate limiting or lockout, allowing bypass of the web login protections. Fingerprintable targets and observables are centered on the default router management address `192.168.0.1`, SSH on port 22, and the management hostname `tplinkwifi.net` mentioned in the documentation. Overall, this is a focused operational PoC demonstrating a network-adjacent login rate-limit bypass via SSH-based password oracle abuse on vulnerable TP-Link Archer C64 firmware versions prior to 1.15.0 Build 250729.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.