NONE · 0

CVE-2026-10562

An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of user-supplied URL input within the web interface.  An unauthenticated attacker can ...

Vulnerability Description

An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of user-supplied URL input within the web interface.  An unauthenticated attacker can craft URLs containing URL-encoded path traversal sequences. When processed by the embedded web server, these inputs may cause the device to respond with HTTP 3xx redirects to attacker-controlled external domains. This issue affects Archer AX20 V2.0: through 2.1.9 Build 20230829.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-10562?

CVE-2026-10562 is a documented vulnerability. An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of user-supplied URL input within the web interface.  An unauthenticated attacker can ...

How severe is CVE-2026-10562?

CVSS scoring is not yet available for CVE-2026-10562. Check NVD for updates.

Is there a patch for CVE-2026-10562?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.