Home

Description

When configured as L2TP/IPSec VPN server, Archer AXE75 V1 may accept connections using L2TP without IPSec protection, even when IPSec is enabled. This allows VPN sessions without encryption, exposing data in transit and compromising confidentiality.

PUBLISHED Reserved 2026-01-05 | Published 2026-02-03 | Updated 2026-02-04 | Assigner TPLink




MEDIUM: 6.0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-693 Protection Mechanism Failure

Product status

Default status
unaffected

Any version before <1.5.1 Build 20251202
affected

Credits

Henry Martinez finder

References

www.tp-link.com/en/support/download/archer-axe75/v1/ patch

www.tp-link.com/us/support/download/archer-axe75/v1/ patch

www.tp-link.com/us/support/faq/4942/ vendor-advisory

cve.org (CVE-2026-0620)

nvd.nist.gov (CVE-2026-0620)

Download JSON