Impact
A missing authentication flaw in the VPN configuration management subsystem of TP‑Link routers allows a remote unauthenticated attacker to read and modify VPN configuration details. The vulnerability stems from improper access control, meaning that authentication is not required to perform configuration changes, which could lead to exposure or tampering of sensitive VPN settings.
Affected Systems
The flaw affects TP‑Link Systems Inc. Archer MR600 models (firmware versions v2, v3, and v5) and the TL‑MR6400 v8. All affected routers can reach the vulnerable configuration management endpoint remotely without credentials.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. However, the vulnerability is exploitable remotely by unauthenticated actors, security.
OpenCVE Enrichment