CVE-2026-76653 PUBLISHED

Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR600

Assigner: TPLink
Reserved: 19.08.2026 Published: 10.09.2026 Updated: 10.09.2026

A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials.

Successful exploitation may allow a remote unauthenticated attacker to disclose and modify VPN configuration information.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor TP-Link Systems Inc.
Product TL-MR6400 v8
Versions Default: unaffected
  • affected from 0 to 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n (excl.)
Vendor TP-Link Systems Inc.
Product Archer MR600
Versions Default: unaffected
  • affected from v3 to MR600(EU)_V3_1.4.0 Build 260827 (excl.)
  • affected from v2 to MR600(EU)_V2_1.12.0 Build 2600826 (excl.)

Credits

  • Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications finder

References

Problem Types

  • CWE-126 CWE

Impacts

  • CAPEC-126 Path Traversal