SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-76653

MEDIUM · CVSS 5.3 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A vulnerability in the VPN configuration management of Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 allows remote unauthenticated attackers to access and modify VPN settings due to improper access control. This could lead to unauthorized disclosure of sensitive information and potential manipulation of the VPN configuration. Organizations using these devices should prioritize patching this vulnerability to safeguard their network integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76653
Severity
MEDIUM
CVSS
5.3
EPSS
0.30%

Original NVD Description

A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials. Successful exploitation may allow a remote unauthenticated attacker to disclose and modify VPN configuration information.