CyberRota Analysis
AI-GeneratedAn authenticated directory traversal vulnerability exists in the file upload functionality of Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 devices, allowing attackers to upload specially crafted files that can be written outside the intended directory due to insufficient validation of user-supplied file information. This could lead to unauthorized file modifications or overwrites, potentially impacting the integrity of the affected service. Organizations using these devices should prioritize addressing this vulnerability to mitigate risks associated with unauthorized file access and manipulation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected upload functionality could upload a specially crafted file and cause it to be written outside the intended directory. Successful exploitation could allow an authenticated remote attacker to write files to unintended locations, potentially overwriting or modifying files accessible to the affected service; arbitrary code execution has not been demonstrated.