CVE-2026-76653

Summary

A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials.

Successful exploitation may allow a remote unauthenticated attacker to disclose and modify VPN configuration information.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.TL-MR6400 v80 < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978naffected
TP-Link Systems Inc.Archer MR600v3 < MR600(EU)_V3_1.4.0 Build 260827affected
TP-Link Systems Inc.Archer MR600v2 < MR600(EU)_V2_1.12.0 Build 2600826affected

Weaknesses

  • CWE-126: CWE-126

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References