5.3

CVE-2026-76653

Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR600

A missing
authentication vulnerability in the VPN configuration management has been
identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker
may be able to access and modify VPN configuration information without valid
credentials.









Successful
exploitation may allow a remote unauthenticated attacker to disclose and modify
VPN configuration information.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerTP-Link Systems Inc.
≫
Produkt TL-MR6400 v8
Default Statusunaffected
Version 0
Version < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n
Status affected
HerstellerTP-Link Systems Inc.
≫
Produkt Archer MR600
Default Statusunaffected
Version v3
Version < MR600(EU)_V3_1.4.0 Build 260827
Status affected
Version v2
Version < MR600(EU)_V2_1.12.0 Build 2600826
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.223
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
f23511db-6c3e-4e32-a477-6aa17d310630 5.3 0 0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-126 Buffer Over-read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware
https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware
https://www.tp-link.com/us/support/faq/5292/