Impact
An authenticated directory traversal flaw allows a user with access to the router’s file upload feature to craft a file whose path causes the device to write the file outside the intended directory. This can overwrite or modify system files that are normally protected, potentially disrupting router services or altering configuration data. No confirmed arbitrary code execution has been demonstrated, but the integrity of critical files could be compromised.
Affected Systems
TP‑Link Archer MR600 running firmware versions 2, 3, and 5, as well as the TL‑MR6400 running firmware release v8, are affected by this vulnerability. The flaw resides in the file upload functionality of these devices.
Risk and Exploitability
The vulnerability has a medium severity CVSS score of 4.8. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. It requires authentication and remote access to the specific upload feature; an attacker with such access can write files to unintended locations, which may lead to integrity violations of service‑related files. The lack of demonstrated arbitrary code execution limits the impact to potential modification of existing files rather than full system compromise.
OpenCVE Enrichment