
CVE-2026-1571 User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbitrary JavaScript execution via a crafted URL. An … https://www.cve.org/CVERecord?id=CVE-2026-1571
Post summary
The CVE-2026-1571 describes a reflected XSS vulnerability in the TP‑Link Archer C60 v3 that allows arbitrary JavaScript execution through a crafted URL. No PoC, exploit code, patch, or evidence of active exploitation is mentioned.

