CVE-2026-0620
Unknown
Unknown - Not Provided
L2TP Without IPSec Encryption Vulnerability in Archer AXE75 VPN
Publication date: 2026-02-03
Last updated on: 2026-02-03
Assigner: TPLink
Description
Description
When configured as L2TP/IPSec VPN server, Archer AXE75 V1 may accept connections using L2TP without IPSec protection, even when IPSec is enabled. This allows VPN sessions without encryption, exposing data in transit and compromising confidentiality.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tp-link | archer_axe75 | to 1.5.1_build_20251202 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-693 | The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. |