Description
A missing
authentication vulnerability in the VPN configuration management has been
identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker
may be able to access and modify VPN configuration information without valid
credentials.









Successful
exploitation may allow a remote unauthenticated attacker to disclose and modify
VPN configuration information.
Published: 2026-09-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Configuration Access
Action: Immediate Patch
AI Analysis

Impact

A missing authentication flaw in the VPN configuration management subsystem of TP‑Link routers allows a remote unauthenticated attacker to read and modify VPN configuration details. The vulnerability stems from improper access control, meaning that authentication is not required to perform configuration changes, which could lead to exposure or tampering of sensitive VPN settings.

Affected Systems

The flaw affects TP‑Link Systems Inc. Archer MR600 models (firmware versions v2, v3, and v5) and the TL‑MR6400 v8. All affected routers can reach the vulnerable configuration management endpoint remotely without credentials.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. However, the vulnerability is exploitable remotely by unauthenticated actors, security.

Generated by OpenCVE AI on September 10, 2026 at 22:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the access to VPN configuration management for Archer MR600 and TL‑MR6400 devices.
  • If an update is not immediately available, block or restrict access to the router’s configuration management interface from untrusted networks or disable the VPN configuration feature through a firewall or access control list.
  • Ensure that the router is properly segmented, and non‑essential management ports protected from potential attackers.

Generated by OpenCVE AI on September 10, 2026 at 22:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link archer Mr600
Tp-link tl-mr6400 V8
Vendors & Products Tp-link
Tp-link archer Mr600
Tp-link tl-mr6400 V8

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials. Successful exploitation may allow a remote unauthenticated attacker to disclose and modify VPN configuration information.
Title Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR600
Weaknesses CWE-126
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Archer Mr600 Tl-mr6400 V8
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-09-10T20:27:18.091Z

Reserved: 2026-08-19T15:49:30.548Z

Link: CVE-2026-76653

cve-icon Vulnrichment

Updated: 2026-09-10T20:27:15.424Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T21:17:45.433

Modified: 2026-09-11T15:21:12.850

Link: CVE-2026-76653

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:59:41Z

Weaknesses