CVE-2026-76652

Summary

An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected upload functionality could upload a specially crafted file and cause it to be written outside the intended directory.

Successful exploitation could allow an authenticated remote attacker to write files to unintended locations, potentially overwriting or modifying files accessible to the affected service; arbitrary code execution has not been demonstrated.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.TL-MR6400 v80 < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978naffected
TP-Link Systems Inc.Archer MR600v3 < MR600(EU)_V3_1.4.0 Build 260827affected
TP-Link Systems Inc.Archer MR600v5 < MR600(EU)_V5_1.9.0 Build 260805affected
TP-Link Systems Inc.Archer MR600v2 < MR600(EU)_V2_1.12.0 Build 2600826affected

Weaknesses

  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References