Security Advisory: Multiple Vulnerabilities in TP-Link Archer MR600 and TL-MR6400 (CVE-2026-76652 & CVE-2026-76653)
Description of Vulnerabilities and Impacts:
TP-Link has identified two vulnerabilities affecting file upload and VPN configuration management in Archer MR600 and TL-MR6400 v8.
CVE-2026-76652: Authenticated Directory Traversal Vulnerability in File Upload Functionality
An authenticated directory traversal vulnerability in file upload functionality has been identified. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected upload functionality could upload a specially crafted file and cause it to be written outside the intended directory.
Successful exploitation could allow an authenticated remote attacker to write files to unintended locations, potentially overwriting or modifying files accessible to the affected service; arbitrary code execution has not been demonstrated.
CVSS v4.0 Score: 4.8/ Medium
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVE-2026-76653: Missing Authentication in VPN Configuration Management
A missing authentication vulnerability in the VPN configuration management has been identified due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials.
Successful exploitation may allow a remote unauthenticated attacker to disclose and modify VPN configuration information.
CVSS v4.0 Score: 5.3/ Medium
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products/Versions and Fixes:
|
Affected Product |
Hardware Version |
CVEs |
Fixed Version |
|
TL-MR6400 |
V8 |
CVE-2026-76652 CVE-2026-76653 |
1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n |
|
Archer MR600 |
V2 |
CVE-2026-76652 CVE-2026-76653 |
MR600(EU)_V2_1.12.0 Build 2600826 |
|
Archer MR600 |
V3 |
CVE-2026-76652 CVE-2026-76653 |
MR600(EU)_V3_1.4.0 Build 260827 |
|
Archer MR600 |
V5 |
CVE-2026-76652 |
MR600(EU)_V5_1.9.0 Build 260805 |
Recommendations:
We strongly recommend that users with affected devices take the following actions:
- Follow the instructions to update to the latest firmware version to fix the vulnerabilities:
EN: Download for Archer MR600 | TP-Link
Download for TL-MR6400 | TP-Link
Note: Archer MR600 and TL-MR6400 are not sold in the US.
Disclaimer:
This advisory is provided for informational purposes only and is subject to change without notice. The information is provided “as is” without warranties of any kind. TP-Link recommends that customers promptly apply available firmware updates or implement documented workarounds as provided in this advisory. Devices/systems that are not updated or mitigated as described may remain vulnerable, and TP-Link disclaims any responsibility or liability for any damages or losses arising from a failure to implement such updates.
Looking For More
Is this faq useful?
Your feedback helps improve this site.
TP-Link Community
Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.