CVE-2026-0620
Severity CVSS v4.0:
MEDIUM
Type:
CWE-693
Protection Mechanism Failure
Publication date:
03/02/2026
Last modified:
03/02/2026
Description
When configured as L2TP/IPSec VPN server, Archer AXE75 V1 may accept connections using L2TP without IPSec protection, even when IPSec is enabled. This allows VPN sessions without encryption, exposing data in transit and compromising confidentiality.
Impact
Base Score 4.0
6.00
Severity 4.0
MEDIUM



