---
id: CVE-2026-76652
title: >-
  An

  authenticated directory traversal vulnerability in file upload functionality
  has

  been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8
summary: >-
  An

  authenticated directory traversal vulnerability in file upload functionality
  has

  been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to
  insufficient validation of user-supplied file

  information, an authenticated remote…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-22
vendor: TP-Link Systems Inc.
product: TL-MR6400 v8
affected:
  - tl-mr6400_v8 < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n
  - archer_mr600 >= v3 < MR600(EU)_V3_1.4.0 Build 260827
  - archer_mr600 >= v5 < MR600(EU)_V5_1.9.0 Build 260805
  - archer_mr600 >= v2 < MR600(EU)_V2_1.12.0 Build 2600826
published: '2026-09-10'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T15:21:12.850'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76652'
references:
  - url: 'https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/faq/5292/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T20:26:30.638965Z'
cvssSource: cna
ingestedAt: '2026-09-12T15:55:50.697Z'
epss: 0.00732
epssPercentile: 0.52297
---

## Overview

An
authenticated directory traversal vulnerability in file upload functionality has
been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file
information, an authenticated remote attacker with access to the affected
upload functionality could upload a specially crafted file and cause it to be
written outside the intended directory. 





Successful
exploitation could allow an authenticated remote attacker to write files to
unintended locations, potentially overwriting or modifying files
accessible to the affected service; arbitrary code execution has not
been demonstrated.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
