{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-76652","assignerOrgId":"f23511db-6c3e-4e32-a477-6aa17d310630","state":"PUBLISHED","assignerShortName":"TPLink","dateReserved":"2026-08-19T15:49:30.548Z","datePublished":"2026-09-10T20:12:50.706Z","dateUpdated":"2026-09-10T20:27:00.302Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f23511db-6c3e-4e32-a477-6aa17d310630","shortName":"TPLink","dateUpdated":"2026-09-10T20:12:50.706Z"},"title":"Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-126","descriptions":[{"lang":"en","value":"CAPEC-126 Path Traversal"}]}],"affected":[{"vendor":"TP-Link Systems Inc.","product":"TL-MR6400 v8","platforms":["Linux"],"versions":[{"status":"affected","version":"0","lessThan":"1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"Archer MR600","platforms":["Linux"],"versions":[{"status":"affected","version":"v3","lessThan":"MR600(EU)_V3_1.4.0 Build 260827","versionType":"custom"},{"status":"affected","version":"v5","lessThan":"MR600(EU)_V5_1.9.0 Build 260805","versionType":"custom"},{"status":"affected","version":"v2","lessThan":"MR600(EU)_V2_1.12.0 Build 2600826","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"An\nauthenticated directory traversal vulnerability in file upload functionality has\nbeen identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file\ninformation, an authenticated remote attacker with access to the affected\nupload functionality could upload a specially crafted file and cause it to be\nwritten outside the intended directory. \n\n\n\n\n\nSuccessful\nexploitation could allow an authenticated remote attacker to write files to\nunintended locations, potentially overwriting or modifying files\naccessible to the affected service; arbitrary code execution has not\nbeen demonstrated.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>An\nauthenticated directory traversal vulnerability in file upload functionality has\nbeen identified in Archer MR600 (v2, v3 &amp; v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file\ninformation, an authenticated remote attacker with access to the affected\nupload functionality could upload a specially crafted file and cause it to be\nwritten outside the intended directory. </p>\n\n<p>Successful\nexploitation could allow an authenticated remote attacker to write files to\nunintended locations, potentially overwriting or&nbsp;modifying&nbsp;files\naccessible to the affected service; arbitrary code execution has not\nbeen&nbsp;demonstrated.&nbsp;</p>"}]}],"references":[{"url":"https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware","tags":["patch"]},{"url":"https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware","tags":["patch"]},{"url":"https://www.tp-link.com/us/support/faq/5292/","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":4.8,"vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}}],"credits":[{"lang":"en","value":"Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-10T20:26:30.638965Z","id":"CVE-2026-76652","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-10T20:27:00.302Z"}}]}}