VYPR
Vypr IntelligenceAI-generatedSep 11, 2026· 3 CVEs

TP-Link: Three Network Device Vulnerabilities Disclosed, Including Command Injection

TP-Link devices affected by a batch of three vulnerabilities, including critical command injection and VPN configuration flaws.

Key findings

  • High-severity OS command injection in TP-Link Deco BE11000 via crafted UDP packet.
  • Medium-severity missing authentication in VPN config management for Archer MR600 and TL-MR6400.
  • Authenticated directory traversal in file upload for Archer MR600 and TL-MR6400.
  • Vulnerabilities disclosed within a 3-hour window on September 10-11, 2026.

On September 11, 2026, a batch of three vulnerabilities was disclosed, affecting TP-Link networking devices. The vulnerabilities, disclosed within a three-hour window, include a critical OS command injection flaw in the TDDP module of the Deco BE11000, and two medium-severity vulnerabilities affecting Archer MR600 and TL-MR6400 routers. The disclosures highlight potential risks to device integrity and data security for users of these TP-Link products.

The most severe vulnerability, CVE-2026-17176, is an OS command injection flaw within the TDDP module of the TP-Link Deco BE11000. This high-severity issue allows an attacker within the adjacent network to send a crafted UDP packet and execute arbitrary commands with root privileges. Successful exploitation could lead to a complete compromise of the affected device, enabling unauthorized command execution and data modification.

Two medium-severity vulnerabilities were also disclosed on September 10, 2026, impacting multiple Archer and TL-MR series routers. CVE-2026-76653 is a missing authentication vulnerability in the VPN configuration management of Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. This flaw allows unauthenticated remote attackers to access and modify VPN configuration details without proper credentials. Additionally, CVE-2026-76652, an authenticated directory traversal vulnerability in the file upload functionality of the same router models, permits authenticated attackers to upload specially crafted files, potentially leading to unauthorized access or system manipulation due to insufficient validation of user-supplied file information.

The disclosed vulnerabilities present a significant risk to users of the affected TP-Link devices. The OS command injection flaw in the Deco BE11000 could grant attackers full control over the device, while the vulnerabilities in the Archer and TL-MR routers could expose sensitive VPN configurations and allow for unauthorized file uploads. Users are advised to consult TP-Link's official advisories for specific mitigation steps and firmware updates to protect their networks from these potential threats.

This batch of disclosures underscores the importance of timely patching and security awareness for network infrastructure. Users of the affected TP-Link devices should prioritize applying any available updates to safeguard their devices against these newly identified security weaknesses.

AI-written article. Grounded in 3 CVE records listed below.