CVE-2026-0620

When configured as L2TP/IPSec VPN server, Archer AXE75 V1 may accept connections using L2TP without IPSec protection, even when IPSec is enabled.  This allows VPN sessions without encryption, exposing data in transit and compromising confidentiality.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Feb 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 19:16

Updated : 2026-02-03 19:16


NVD link : CVE-2026-0620

Mitre link : CVE-2026-0620

CVE.ORG link : CVE-2026-0620


JSON object : View

Products Affected

No product.

CWE
CWE-693

Protection Mechanism Failure