{"id":"CVE-2026-76652","title":"An\nauthenticated directory traversal vulnerability in file upload functionality has\nbeen identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8","summary":"An\nauthenticated directory traversal vulnerability in file upload functionality has\nbeen identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file\ninformation, an authenticated remote…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-22"],"vendor":"TP-Link Systems Inc.","product":"TL-MR6400 v8","affected":["tl-mr6400_v8 < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n","archer_mr600 >= v3 < MR600(EU)_V3_1.4.0 Build 260827","archer_mr600 >= v5 < MR600(EU)_V5_1.9.0 Build 260805","archer_mr600 >= v2 < MR600(EU)_V2_1.12.0 Build 2600826"],"published":"2026-09-10","updated":"2026-09-11","sourceUpdated":"2026-09-11T15:21:12.850","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76652","references":[{"url":"https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/5292/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T20:26:30.638965Z"},"cvssSource":"cna","ingestedAt":"2026-09-12T15:55:50.697Z","epss":0.00732,"epssPercentile":0.52297,"slug":"CVE-2026-76652","body":"## Overview\n\nAn\nauthenticated directory traversal vulnerability in file upload functionality has\nbeen identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file\ninformation, an authenticated remote attacker with access to the affected\nupload functionality could upload a specially crafted file and cause it to be\nwritten outside the intended directory. \n\n\n\n\n\nSuccessful\nexploitation could allow an authenticated remote attacker to write files to\nunintended locations, potentially overwriting or modifying files\naccessible to the affected service; arbitrary code execution has not\nbeen demonstrated.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":27,"depthScoreParts":{"impact":26.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}