TP-Link TL-MR6400是中国TP-Link公司开源的一款4G无线路由器。 TP-Link TL-MR6400存在路径遍历漏洞,该漏洞源于WebUI ISP Upgrade功能存在Zip Slip漏洞,通过包含目录遍历序列的特制存档允许任意文件写入,可能导致经过身份验证的管理员覆盖系统上的任意文件,影响系统完整性和可用性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | Archer MR200 v7 | < (EU)_1.3.0 0.9.1 v0001.0 Build 260605 Rel.57870n |
affected |
| TP-Link Systems Inc. | Archer MR600 v2 | < (EU)_1.10.0 0.9.1 v0001.0 Build 260618 RC.40417n |
affected |
| TP-Link Systems Inc. | TL-MR100 v3.20 | < (EU)_1.3.0 0.9.1 v0001.0 Build 260609 Rel.49957n |
affected |
< 1.1.0 0.9.1 v0001.0 Build 260609 Rel35479n, Customized Software for South Korea KT |
affected | ||
< 1.2.0 0.9.1 v0001.0 Build 260609 Rel.36250n, Customized Software for South Korea Telenor |
affected | ||
| TP-Link Systems Inc. | TL-MR150 v3.20 | < (EU)_1.3.0 0.9.1 v0001.0 Build 260720 Rel.59727n |
affected |
| TP-Link Systems Inc. | TL-MR6400 v5.3 | < (EU)_1.10.0 0.9.1 v0001.0 Build 260613 RC.76099n |
affected |
| TP-Link Systems Inc. | TL-MR6400 v8.0 | < (EU)_1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v5.3 | 0 ~ (EU)_1.10.0 0.9.1 v0001.0 Build 260613 RC.76099n | - |
|
| TP-Link Systems Inc. | Archer MR600 v2 | 0 ~ (EU)_1.10.0 0.9.1 v0001.0 Build 260618 RC.40417n | - |
|
| TP-Link Systems Inc. | Archer MR200 v7 | 0 ~ (EU)_1.3.0 0.9.1 v0001.0 Build 260605 Rel.57870n | - |
|
| TP-Link Systems Inc. | TL-MR6400 v8.0 | 0 ~ (EU)_1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n | - |
|
| TP-Link Systems Inc. | TL-MR150 v3.20 | 0 ~ (EU)_1.3.0 0.9.1 v0001.0 Build 260720 Rel.59727n | - |
|
| TP-Link Systems Inc. | TL-MR100 v3.20 | 0 ~ (EU)_1.3.0 0.9.1 v0001.0 Build 260609 Rel.49957n | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-30237 | 8.7 HIGH | Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet D |
| CVE-2025-30241 | 8.6 HIGH | OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices |
| CVE-2025-30238 | 8.6 HIGH | Privilege Escalation via Improper Authorization in User Management in multiple TP-Link Agi |
| CVE-2025-30239 | 8.5 HIGH | Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet Dev |
| CVE-2025-30240 | 5.1 MEDIUM | Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP- |
No comments yet