Missing Authentication Vulnerability in Archer MR600 and TL-MR6400 by TP-Link
CVE-2026-76653
5.3MEDIUM
Key Information:
- Vendor
Tp-link Systems Inc.
- Status
- Vendor
- CVE Published:
- 10 September 2026
What is CVE-2026-76653?
A vulnerability has been discovered in the VPN configuration management of Archer MR600 (versions 2, 3, and 5) and TL-MR6400 v8. Due to improper access control, a remote attacker without valid credentials can potentially access and alter VPN configuration settings. This may lead to unauthorized disclosure and modification of sensitive VPN information.
Affected Version(s)
Archer MR600 Linux v3
Archer MR600 Linux v2
TL-MR6400 v8 Linux 0 < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications
