6.9
CVE-2026-12339
- EPSS 0.31%
- Veröffentlicht 10.08.2026 18:20:50
- Zuletzt bearbeitet 26.08.2026 05:18:05
- Erkennungen
Authenticated Arbitrary File Write Vulnerability in multiple devices
A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to be overwritten on the underlying system, affecting system integrity and availability.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerTP-Link Systems Inc.
≫
Produkt
TL-MR6400 v5.3
Default Statusunaffected
Version
0
Version <
(EU)_1.10.0 0.9.1 v0001.0 Build 260613 RC.76099n
Status
affected
HerstellerTP-Link Systems Inc.
≫
Produkt
Archer MR600 v2
Default Statusunaffected
Version
0
Version <
(EU)_1.10.0 0.9.1 v0001.0 Build 260618 RC.40417n
Status
affected
HerstellerTP-Link Systems Inc.
≫
Produkt
Archer MR200 v7
Default Statusunaffected
Version
0
Version <
(EU)_1.3.0 0.9.1 v0001.0 Build 260605 Rel.57870n
Status
affected
HerstellerTP-Link Systems Inc.
≫
Produkt
TL-MR6400 v8.0
Default Statusunaffected
Version
0
Version <
(EU)_1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n
Status
affected
HerstellerTP-Link Systems Inc.
≫
Produkt
TL-MR150 v3.20
Default Statusunaffected
Version
0
Version <
(EU)_1.3.0 0.9.1 v0001.0 Build 260720 Rel.59727n
Status
affected
HerstellerTP-Link Systems Inc.
≫
Produkt
TL-MR100 v3.20
Default Statusunaffected
Version
0
Version <
(EU)_1.3.0 0.9.1 v0001.0 Build 260609 Rel.49957n
Status
affected
Version
0
Version <
1.1.0 0.9.1 v0001.0 Build 260609 Rel35479n, Customized Software for South Korea KT
Status
affected
Version
0
Version <
1.2.0 0.9.1 v0001.0 Build 260609 Rel.36250n, Customized Software for South Korea Telenor
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.235 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| f23511db-6c3e-4e32-a477-6aa17d310630 | 6.9 | 0 | 0 |
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
https://www.tp-link.com/en/support/download/tl-mr6400/v5.30/#Firmware
https://www.tp-link.com/en/support/download/archer-mr600/v2/#Firmware
https://www.tp-link.com/en/support/download/archer-mr200/v7/#Firmware
https://www.tp-link.com/en/support/faq/5237/
https://www.tp-link.com/en/support/download/tl-mr100/v3.20/#Firmware
https://www.tp-link.com/en/support/download/tl-mr150/v3.20/#Firmware
https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware
https://www.tp-link.com/kr/support/download/tl-mr100/v3.20/#Firmware