CVE-2026-76653 Details
Description
A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials. Successful exploitation may allow a remote unauthenticated attacker to disclose and modify VPN configuration information.
A missing authentication vulnerability has been identified in the VPN configuration management of TP-Link Archer MR600 (versions 2, 3, and 5) and TL-MR6400 v8. This vulnerability arises from improper access control, allowing remote unauthenticated attackers to access and modify VPN configuration information without valid credentials. Successful exploitation could lead to unauthorized disclosure and modification of VPN settings.
Users are advised to update to the latest firmware version. For Archer MR600 V2, V3, and TL-MR6400 V8, the latest version is 1.5.0. For Archer MR600 V5, the latest version is 1.9.0. Instructions for downloading the firmware are available on the TP-Link support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 10, 2026CISA-ADP
Assessed Sep 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware | TPLink | ProductVendor |
| https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware | TPLink | ProductVendor |
| https://www.tp-link.com/us/support/faq/5292/ | TPLink | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-126 | Buffer Over-read | TPLink |
Affected Products
| Product | Versions |
|---|---|
| TP-Link Archer MR600 | V2 V3 |
CPE
Remediation
| |
| TP-Link TL-MR6400 | V8 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | New CVE Received | TPLink |
| Sep 10, 2026 | CVE Modified | CISA-ADP |
Volerion