VYPR

Archer MR600

by TP-Link

CVEs (6)

  • CVE-2025-14756HigJan 26, 2026
    risk 0.57cvss 8.8epss 0.03

    Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to…

  • CVE-2026-8913HigJun 8, 2026
    risk 0.55cvss —epss 0.02

    A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authenticated attacker with administrative privileges may be able to execute…

  • CVE-2026-8619HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference.  A remote attacker on an…

  • CVE-2026-12339MedAug 10, 2026
    risk 0.45cvss —epss 0.01

    A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file…

  • CVE-2026-76653MedSep 10, 2026
    risk 0.34cvss —epss 0.00

    A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information…

  • CVE-2026-76652MedSep 10, 2026
    risk 0.31cvss —epss 0.01

    An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected…