CVE-2026-76652
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Summary
An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected upload functionality could upload a specially crafted file and cause it to be written outside the intended directory.
Successful exploitation could allow an authenticated remote attacker to write files to unintended locations, potentially overwriting or modifying files accessible to the affected service; arbitrary code execution has not been demonstrated.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v8 | 0 < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n | affected |
| TP-Link Systems Inc. | Archer MR600 | v3 < MR600(EU)_V3_1.4.0 Build 260827 | affected |
| TP-Link Systems Inc. | Archer MR600 | v5 < MR600(EU)_V5_1.9.0 Build 260805 | affected |
| TP-Link Systems Inc. | Archer MR600 | v2 < MR600(EU)_V2_1.12.0 Build 2600826 | affected |
Weaknesses
- CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware
- https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware
- https://www.tp-link.com/us/support/faq/5292/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.