Click to skip the navigation bar

Security Advisory: Multiple Vulnerabilities in TP-Link Archer MR600 and TL-MR6400 (CVE-2026-76652 & CVE-2026-76653)

Security Advisory
Last updated: September 10, 2026

Description of Vulnerabilities and Impacts:

TP-Link has identified two vulnerabilities affecting file upload and VPN configuration management in Archer MR600 and TL-MR6400 v8.

CVE-2026-76652: Authenticated Directory Traversal Vulnerability in File Upload Functionality

An authenticated directory traversal vulnerability in file upload functionality has been identified. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected upload functionality could upload a specially crafted file and cause it to be written outside the intended directory.

Successful exploitation could allow an authenticated remote attacker to write files to unintended locations, potentially overwriting or modifying files accessible to the affected service; arbitrary code execution has not been demonstrated.

CVSS v4.0 Score: 4.8/ Medium

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

CVE-2026-76653: Missing Authentication in VPN Configuration Management

A missing authentication vulnerability in the VPN configuration management has been identified due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials.

Successful exploitation may allow a remote unauthenticated attacker to disclose and modify VPN configuration information.

CVSS v4.0 Score: 5.3/ Medium

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products/Versions and Fixes:

Affected Product

Hardware Version

CVEs

Fixed Version

TL-MR6400

V8

CVE-2026-76652

CVE-2026-76653

1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n

Archer MR600

V2

CVE-2026-76652

CVE-2026-76653

MR600(EU)_V2_1.12.0 Build 2600826

Archer MR600

V3

CVE-2026-76652

CVE-2026-76653

MR600(EU)_V3_1.4.0 Build 260827

Archer MR600

V5

CVE-2026-76652

MR600(EU)_V5_1.9.0 Build 260805

Recommendations:

We strongly recommend that users with affected devices take the following actions:

  1. Follow the instructions to update to the latest firmware version to fix the vulnerabilities:

EN: Download for Archer MR600 | TP-Link

Download for TL-MR6400 | TP-Link

Note: Archer MR600 and TL-MR6400 are not sold in the US.

Disclaimer:

This advisory is provided for informational purposes only and is subject to change without notice. The information is provided “as is” without warranties of any kind. TP-Link recommends that customers promptly apply available firmware updates or implement documented workarounds as provided in this advisory. Devices/systems that are not updated or mitigated as described may remain vulnerable, and TP-Link disclaims any responsibility or liability for any damages or losses arising from a failure to implement such updates.

Related FAQs

Looking For More

Is this faq useful?

Your feedback helps improve this site.

Community

TP-Link Community

Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.

Visit the Community >