CVE-2026-0620

MEDIUM

Archer AXE75 V1 - Info Disclosure

Title source: llm
STIX 2.1

Description

When configured as L2TP/IPSec VPN server, Archer AXE75 V1 may accept connections using L2TP without IPSec protection, even when IPSec is enabled.  This allows VPN sessions without encryption, exposing data in transit and compromising confidentiality.

Scores

CVSS v4 6.0
EPSS 0.0006
EPSS Percentile 18.4%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-693
Status published
Products (1)
TP-Link Systems Inc./AXE75 < <1.5.1 Build 20251202
Published Feb 03, 2026
Tracked Since Feb 18, 2026