SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-76652

MEDIUM · CVSS 4.8 EPSS 0.53% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

An authenticated directory traversal vulnerability exists in the file upload functionality of Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 devices, allowing attackers to upload specially crafted files that can be written outside the intended directory due to insufficient validation of user-supplied file information. This could lead to unauthorized file modifications or overwrites, potentially impacting the integrity of the affected service. Organizations using these devices should prioritize addressing this vulnerability to mitigate risks associated with unauthorized file access and manipulation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76652
Severity
MEDIUM
CVSS
4.8
EPSS
0.53%

Original NVD Description

An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected upload functionality could upload a specially crafted file and cause it to be written outside the intended directory. Successful exploitation could allow an authenticated remote attacker to write files to unintended locations, potentially overwriting or modifying files accessible to the affected service; arbitrary code execution has not been demonstrated.