---
id: CVE-2026-76653
title: "A missing\nauthentication vulnerability in the VPN configuration management has been\nidentified\_in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8\_due to improper access control; a remote unauthenticated attacker\nmay be able to access and mod…"
summary: "A missing\nauthentication vulnerability in the VPN configuration management has been\nidentified\_in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8\_due to improper access control; a remote unauthenticated attacker\nmay be able to access and mod…"
severity: medium
cvss: 5.3
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-126
vendor: TP-Link Systems Inc.
product: TL-MR6400 v8
affected:
  - tl-mr6400_v8 < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n
  - archer_mr600 >= v3 < MR600(EU)_V3_1.4.0 Build 260827
  - archer_mr600 >= v2 < MR600(EU)_V2_1.12.0 Build 2600826
published: '2026-09-10'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T15:21:12.850'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76653'
references:
  - url: 'https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/faq/5292/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T20:27:12.333163Z'
cvssSource: cna
ingestedAt: '2026-09-13T18:56:50.864Z'
epss: 0.00474
epssPercentile: 0.38403
---

## Overview

A missing
authentication vulnerability in the VPN configuration management has been
identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker
may be able to access and modify VPN configuration information without valid
credentials.









Successful
exploitation may allow a remote unauthenticated attacker to disclose and modify
VPN configuration information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
