CVE-2026-76652
- EPSS 0.53%
- Veröffentlicht 10.09.2026 20:12:50
- Zuletzt bearbeitet 11.09.2026 15:21:12
An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker wit...
CVE-2026-76653
- EPSS 0.3%
- Veröffentlicht 10.09.2026 20:12:43
- Zuletzt bearbeitet 11.09.2026 15:21:12
A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN confi...
CVE-2026-8619
- EPSS 0.28%
- Veröffentlicht 19.08.2026 23:11:51
- Zuletzt bearbeitet 03.09.2026 15:04:30
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A ...
CVE-2026-12339
- EPSS 0.31%
- Veröffentlicht 10.08.2026 18:20:50
- Zuletzt bearbeitet 26.08.2026 05:18:05
A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploita...
CVE-2026-8913
- EPSS 0.91%
- Veröffentlicht 08.06.2026 17:21:45
- Zuletzt bearbeitet 23.07.2026 08:10:00
A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authenticated attacker with administrative privileges ma...