CVE-2026-76652 PUBLISHED

Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600

Assigner: TPLink
Reserved: 19.08.2026 Published: 10.09.2026 Updated: 10.09.2026

An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected upload functionality could upload a specially crafted file and cause it to be written outside the intended directory.

Successful exploitation could allow an authenticated remote attacker to write files to unintended locations, potentially overwriting or modifying files accessible to the affected service; arbitrary code execution has not been demonstrated.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 4.8

Product Status

Vendor TP-Link Systems Inc.
Product TL-MR6400 v8
Versions Default: unaffected
  • affected from 0 to 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n (excl.)
Vendor TP-Link Systems Inc.
Product Archer MR600
Versions Default: unaffected
  • affected from v3 to MR600(EU)_V3_1.4.0 Build 260827 (excl.)
  • affected from v5 to MR600(EU)_V5_1.9.0 Build 260805 (excl.)
  • affected from v2 to MR600(EU)_V2_1.12.0 Build 2600826 (excl.)

Credits

  • Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications finder

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE

Impacts

  • CAPEC-126 Path Traversal