4.8

CVE-2026-76652

Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600

An
authenticated directory traversal vulnerability in file upload functionality has
been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file
information, an authenticated remote attacker with access to the affected
upload functionality could upload a specially crafted file and cause it to be
written outside the intended directory. 





Successful
exploitation could allow an authenticated remote attacker to write files to
unintended locations, potentially overwriting or modifying files
accessible to the affected service; arbitrary code execution has not
been demonstrated.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerTP-Link Systems Inc.
≫
Produkt TL-MR6400 v8
Default Statusunaffected
Version 0
Version < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n
Status affected
HerstellerTP-Link Systems Inc.
≫
Produkt Archer MR600
Default Statusunaffected
Version v3
Version < MR600(EU)_V3_1.4.0 Build 260827
Status affected
Version v5
Version < MR600(EU)_V5_1.9.0 Build 260805
Status affected
Version v2
Version < MR600(EU)_V2_1.12.0 Build 2600826
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.429
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
f23511db-6c3e-4e32-a477-6aa17d310630 4.8 0 0
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware
https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware
https://www.tp-link.com/us/support/faq/5292/