5.2
CVE-2026-12001
- EPSS 0.25%
- Veröffentlicht 27.07.2026 20:08:50
- Zuletzt bearbeitet 11.08.2026 21:17:25
- Erkennungen
Hardcoded Credential Vulnerability in Multiple TP-Link Router Models
A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis. Successful exploitation could result in unauthorized access to privileged functions on affected devices.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerTP-Link Systems Inc.
≫
Produkt
TL-WR850N v3
Default Statusunaffected
Version
0
Version <
TL-WR850N(IN)_V3.48_3.16.0 Build 260422_2048
Status
affected
HerstellerTP-Link Systems Inc.
≫
Produkt
Archer C20 v6
Default Statusunaffected
Version
0
Version <
Archer C20(US)_V6_250630
Status
affected
HerstellerTP Link Systems Inc.
≫
Produkt
TL-WR845N v4
Default Statusunaffected
Version
0
Version <
TL-WR845N(UN)_V4_250401
Status
affected
HerstellerTP-Link Systems Inc.
≫
Produkt
Archer MR200 v5
Default Statusunaffected
Version
0
Version <
EU_V5.20_1.3.0 Build 260319
Status
affected
HerstellerTP Link Systems Inc.
≫
Produkt
TL-WR902AC v4
Default Statusunaffected
Version
0
Version <
US_V4_0.9.1 Build 260810
Status
affected
Version
0
Version <
EU_V4_0.9.3 Build 260728
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.166 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| f23511db-6c3e-4e32-a477-6aa17d310630 | 5.2 | 0 | 0 |
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
https://www.tp-link.com/en/support/download/archer-mr200/v5/#Firmware
https://www.tp-link.com/in/support/download/archer-mr200/v5/#Firmware
https://www.tp-link.com/en/support/download/archer-c20/v6/#Firmware
https://www.tp-link.com/us/support/download/archer-c20/v6/#Firmware
https://www.tp-link.com/in/support/download/archer-c20/v6/#Firmware
https://www.tp-link.com/en/support/download/tl-wr845n/#Firmware
https://www.tp-link.com/in/support/download/tl-wr845n/#Firmware
https://www.tp-link.com/in/support/download/tl-wr850n/#Firmware
https://www.tp-link.com/us/support/faq/5210/
https://www.tp-link.com/en/support/download/tl-wr902ac/v4/#Firmware
https://www.tp-link.com/us/support/download/tl-wr902ac/v4/#Firmware