CVE-2026-76653: TP-Link Systems Inc Archer MR600
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials. Successful exploitation may allow a remote unauthenticated attacker to disclose and modify VPN configuration information.
Affected products
- TP-Link Systems Inc Archer MR600
- TP-Link Systems Inc Tl-MR6400 v8
Published 2026-09-10. Last modified 2026-09-11.