Impact
The vulnerability is a Zip Slip flaw in the WebUI ISP Upgrade functionality that allows an authenticated administrator to craft a malicious ZIP archive containing directory traversal sequences, resulting in arbitrary file writes on the system. This can compromise the device’s integrity by overwriting critical configuration or binaries, and can lead to availability disruptions if essential files are replaced or removed. The weakness is a classic file‑path traversal (CWE‑22).
Affected Systems
TP‑Link Archer MR200 v7, TP‑Link Archer MR600 v2, and TP‑Link TL‑MR6400 v5.3 are affected. These models expose the WebUI ISP Upgrade feature with no input validation for archive paths. The issue is present in the firmware versions listed above.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate severity due to the need for authenticated access and lack of public exploitation evidence (EPSS not available). The vulnerability is not listed in CISA KEV, showing no confirmed publicly disclosed exploits. An attacker who gains administrator credentials or can trick a legitimate administrator into uploading a crafted package can execute the exploit. The attack vector is local or remote via the WebUI, requiring network connectivity to the device.
OpenCVE Enrichment