Description
An
authenticated directory traversal vulnerability in file upload functionality has
been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file
information, an authenticated remote attacker with access to the affected
upload functionality could upload a specially crafted file and cause it to be
written outside the intended directory.





Successful
exploitation could allow an authenticated remote attacker to write files to
unintended locations, potentially overwriting or modifying files
accessible to the affected service; arbitrary code execution has not
been demonstrated.
Published: 2026-09-10
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated directory traversal leading to unintended file writes
Action: Apply Patch
AI Analysis

Impact

An authenticated directory traversal flaw allows a user with access to the router’s file upload feature to craft a file whose path causes the device to write the file outside the intended directory. This can overwrite or modify system files that are normally protected, potentially disrupting router services or altering configuration data. No confirmed arbitrary code execution has been demonstrated, but the integrity of critical files could be compromised.

Affected Systems

TP‑Link Archer MR600 running firmware versions 2, 3, and 5, as well as the TL‑MR6400 running firmware release v8, are affected by this vulnerability. The flaw resides in the file upload functionality of these devices.

Risk and Exploitability

The vulnerability has a medium severity CVSS score of 4.8. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. It requires authentication and remote access to the specific upload feature; an attacker with such access can write files to unintended locations, which may lead to integrity violations of service‑related files. The lack of demonstrated arbitrary code execution limits the impact to potential modification of existing files rather than full system compromise.

Generated by OpenCVE AI on September 10, 2026 at 22:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the router firmware to the latest TP‑Link release that resolves the directory traversal flaw.
  • Restrict the use of the upload functionality to administrative accounts only.
  • Implement monitoring or audit logging to detect unauthorized file creation or modification outside intended directories.

Generated by OpenCVE AI on September 10, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link archer Mr600
Tp-link tl-mr6400 V8
Vendors & Products Tp-link
Tp-link archer Mr600
Tp-link tl-mr6400 V8

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected upload functionality could upload a specially crafted file and cause it to be written outside the intended directory. Successful exploitation could allow an authenticated remote attacker to write files to unintended locations, potentially overwriting or modifying files accessible to the affected service; arbitrary code execution has not been demonstrated.
Title Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Archer Mr600 Tl-mr6400 V8
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-09-10T20:27:00.302Z

Reserved: 2026-08-19T15:49:30.548Z

Link: CVE-2026-76652

cve-icon Vulnrichment

Updated: 2026-09-10T20:26:57.726Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T21:17:44.683

Modified: 2026-09-11T15:21:12.850

Link: CVE-2026-76652

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:59:39Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')