VYPR

TL-MR6400

by TP-Link

CVEs (2)

  • CVE-2026-3841HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.02

    A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient sanitization of data processed during specific CLI operations. An authenticated attacker with elevated privileges…

  • CVE-2026-12339MedAug 10, 2026
    risk 0.45cvss epss

    A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file…