在 Archer MR600(v2、v3 和 v5)以及 TL-MR6400 v8 版本的 VPN 配置管理中,已发现一处认证缺失漏洞,其根源在于访问控制机制不当;未经身份验证的远程攻击者可能无需有效凭据即可访问并修改 VPN 配置信息。 成功利用该漏洞后,未经身份验证的远程攻击者可披露并修改 VPN 配置信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v8 | 0 ~ 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n | - |
|
| TP-Link Systems Inc. | Archer MR600 | v3 ~ MR600(EU)_V3_1.4.0 Build 260827 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-17176 | 7.7 HIGH | OS command injection Vulnerability in Deco BE11000 |
| CVE-2026-84941 | 6.9 MEDIUM | Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading |
| CVE-2026-76652 | 4.8 MEDIUM | Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL |
No comments yet