CVE-2026-76652
An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected upload functionality could upload a specially crafted file and cause it to be written outside the intended directory. Successful exploitation could allow an authenticated remote attacker to write files to unintended locations, potentially overwriting or modifying files accessible to the affected service; arbitrary code execution has not been demonstrated.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.8
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- CWE
- CWE-22
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- TP-Link Systems Inc. TL-MR6400 v8
- TP-Link Systems Inc. Archer MR600
- TP-Link Systems Inc. Archer MR600
- TP-Link Systems Inc. Archer MR600
Weakness type
Related vulnerabilities
- CVE-2026-85706 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
- CVE-2026-90445 — An interface that accepts file uploads from authenticated users extracts the contents of uploaded...
- CVE-2026-49846 — libks has path traversal in kws HTTP parser via URI segment overflow
- CVE-2026-87910 — tarfile hardlink fallback ignores custom extraction filter rejection via None
- CVE-2026-87984 — An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an...
- CVE-2026-87983 — An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an...
- CVE-2026-87727 — a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an...
- CVE-2026-19991 — UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion