Executive brief
TP-Link's Archer MR600 and TL-MR6400 4G/LTE routers are used to provide wireless connectivity and VPN services for small offices and homes. An attacker can remotely access and modify VPN settings without providing valid credentials, potentially exposing VPN configuration details or reconfiguring VPN access to intercept or redirect traffic.
Technical details
The vulnerability is a missing authentication check in the VPN configuration management interface of affected TP-Link routers. The root cause is improper access control that allows unauthenticated remote attackers to read and modify VPN configuration information via direct API or web interface access. The vulnerability is network-reachable and requires no authentication or user interaction. Successful exploitation allows an attacker to view sensitive VPN credentials and configuration, or alter VPN settings to redirect or monitor traffic. Patch availability has not been disclosed in the advisory materials reviewed.
Affected products
- TP-Link Archer MR600 v2, v3, v5
- TP-Link TL-MR6400 v8
Timeline
- 2026-09-10: disclosed