CVE-2026-12339
- EPSS 0.31%
- Veröffentlicht 10.08.2026 18:20:50
- Zuletzt bearbeitet 26.08.2026 05:18:05
A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploita...
CVE-2026-12001
- EPSS 0.25%
- Veröffentlicht 27.07.2026 20:08:50
- Zuletzt bearbeitet 11.08.2026 21:17:25
A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in th...
CVE-2026-11834
- EPSS 1.02%
- Veröffentlicht 22.06.2026 17:53:48
- Zuletzt bearbeitet 26.06.2026 22:16:30
A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient validation of externally supplied DHCP option data. An adjacent attacker may exploit this vulnerability b...