Missing Authentication Vulnerability in Archer MR600 and TL-MR6400 by TP-Link
CVE-2026-76653

5.3MEDIUM

What is CVE-2026-76653?

A vulnerability has been discovered in the VPN configuration management of Archer MR600 (versions 2, 3, and 5) and TL-MR6400 v8. Due to improper access control, a remote attacker without valid credentials can potentially access and alter VPN configuration settings. This may lead to unauthorized disclosure and modification of sensitive VPN information.

Affected Version(s)

Archer MR600 Linux v3

Archer MR600 Linux v2

TL-MR6400 v8 Linux 0 < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications
.