Threats Tagged 'cve-2026-0620'
View all threats tagged with 'cve-2026-0620'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-0620'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-0620 is a medium-severity vulnerability affecting the TP-Link Archer AXE75 router when configured as an L2TP/IPSec VPN server. The device may accept L2TP connections without IPSec protection even if IPSec is enabled, allowing unencrypted VPN sessions. This flaw exposes data in transit, compromising confidentiality. Exploitation requires no privileges but does require user interaction to initiate a VPN connection. There are no known exploits in the wild yet. The vulnerability stems from a protection mechanism failure (CWE-693) in the VPN implementation. European organizations using this router model for VPN services are at risk of data interception. Mitigation involves disabling L2TP-only connections or applying vendor patches once available. Countries with high TP-Link market penetration and critical infrastructure relying on VPNs are most likely affected. Join the discussion | CVE Database V5 | 02/03/2026, 18:05:44 UTC Added: 02/03/2026, 18:30:11 UTC |
Showing 1 to 1 of 1 result