Executive brief
TP-Link's Archer MR600 and TL-MR6400 wireless routers contain a vulnerability in their file upload functionality that allows authenticated users to write files to unintended locations on the device. An attacker with router access could upload a specially crafted file to overwrite or modify critical system files, potentially disrupting router operation or modifying its behavior.
Technical details
This is an authenticated directory traversal vulnerability in the file upload functionality caused by insufficient validation of user-supplied file paths. An authenticated remote attacker with access to the upload feature can craft a malicious file path using directory traversal sequences (e.g., "../") to write files outside the intended upload directory. The vulnerability affects Archer MR600 versions 2, 3, and 5, as well as TL-MR6400 version 8. Successful exploitation allows arbitrary file writing to unintended locations, potentially overwriting system files, though arbitrary code execution has not been demonstrated. The vulnerability requires prior authentication to the affected router's web interface.
Affected products
- TP-Link Archer MR600 v2, v3, v5
- TP-Link TL-MR6400 v8
Timeline
- 2026-09-10: disclosed