Directory Traversal Vulnerability in Archer MR600 and TL-MR6400 by TP-Link
CVE-2026-76652
Key Information:
- Vendor
Tp-link Systems Inc.
- Status
- Vendor
- CVE Published:
- 10 September 2026
What is CVE-2026-76652?
An authenticated directory traversal vulnerability has been discovered in the file upload feature of TP-Link's Archer MR600 and TL-MR6400 routers. This flaw arises from inadequate validation of user-supplied file information, allowing an authenticated remote attacker with access to the upload functionality to upload a maliciously crafted file. Such exploitation could lead to files being written outside the designated directory, potentially overwriting or modifying existing files that are accessible to the affected service. While arbitrary code execution has not been demonstrated, the implications of unintended file placement pose a significant security risk.
Affected Version(s)
Archer MR600 Linux v3
Archer MR600 Linux v5
Archer MR600 Linux v2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
