CVE-2026-76652
- EPSS 0.53%
- Veröffentlicht 10.09.2026 20:12:50
- Zuletzt bearbeitet 11.09.2026 15:21:12
An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker wit...
CVE-2026-76653
- EPSS 0.3%
- Veröffentlicht 10.09.2026 20:12:43
- Zuletzt bearbeitet 11.09.2026 15:21:12
A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN confi...
CVE-2026-17250
- EPSS 0.19%
- Veröffentlicht 21.08.2026 18:16:47
- Zuletzt bearbeitet 28.08.2026 19:02:53
A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlled metadata within a firmware image. Successful exploitation may allow an authenticated attacke...
CVE-2026-17251
- EPSS 0.29%
- Veröffentlicht 21.08.2026 18:16:47
- Zuletzt bearbeitet 28.08.2026 19:02:53
A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of TL-MR6400 v7. An unauthenticated remote attacker can trigger the vulnerability by sending a specially crafted HTTP request containing a malformed session co...
CVE-2026-17252
- EPSS 0.17%
- Veröffentlicht 21.08.2026 18:16:47
- Zuletzt bearbeitet 28.08.2026 19:02:53
A stack-based out-of-bounds write vulnerability exists in the login request handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability by sending a sp...
CVE-2026-8619
- EPSS 0.28%
- Veröffentlicht 19.08.2026 23:11:51
- Zuletzt bearbeitet 03.09.2026 15:04:30
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A ...
CVE-2026-12339
- EPSS 0.31%
- Veröffentlicht 10.08.2026 18:20:50
- Zuletzt bearbeitet 26.08.2026 05:18:05
A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploita...
CVE-2026-11834
- EPSS 1.02%
- Veröffentlicht 22.06.2026 17:53:48
- Zuletzt bearbeitet 26.06.2026 22:16:30
A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient validation of externally supplied DHCP option data. An adjacent attacker may exploit this vulnerability b...