CVE-2026-76652 Details
Description
An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected upload functionality could upload a specially crafted file and cause it to be written outside the intended directory. Successful exploitation could allow an authenticated remote attacker to write files to unintended locations, potentially overwriting or modifying files accessible to the affected service; arbitrary code execution has not been demonstrated.
A directory traversal vulnerability allowing authenticated remote attackers to exploit the file upload feature has been identified in the TP-Link Archer MR600 (versions 2, 3, and 5) and TL-MR6400 v8. The vulnerability arises from inadequate validation of user-supplied file information, enabling attackers to upload specially crafted files that are written outside the designated directory. Exploitation of this vulnerability could lead to unauthorized file modifications or overwrites in locations accessible to the affected service, although arbitrary code execution has not been demonstrated.
Users are advised to update to the latest firmware version. For Archer MR600, the latest version is MR600(EU)_V5_1.9.0 Build 260805. For TL-MR6400, the latest version is TL-MR6400(EN)_V8_1.5.0 Build 260610.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 10, 2026CISA-ADP
Assessed Sep 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware | TPLink | ProductVendor |
| https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware | TPLink | ProductVendor |
| https://www.tp-link.com/us/support/faq/5292/ | TPLink | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | TPLink |
Affected Products
| Product | Versions |
|---|---|
| TP-Link Archer MR600 | >= 2, < 2.1.0 ~3 ~5 |
CPE
Remediation
| |
| TP-Link TL-MR6400 | ~8 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | New CVE Received | TPLink |
| Sep 10, 2026 | CVE Modified | CISA-ADP |
Volerion