Authentication Vulnerability in TP-Link Routers
CVE-2026-12001

5.2MEDIUM

What is CVE-2026-12001?

A security issue has been identified in the firmware of several TP-Link routers where hardcoded credentials are embedded within a password file. This vulnerability allows attackers to recover sensitive authentication information through firmware analysis, potentially granting unauthorized access to privileged functions on the affected devices. Users are strongly advised to update their firmware to mitigate this risk and ensure their devices remain secure.

Affected Version(s)

Archer C20 v6 0

Archer MR200 v5 0

TL-WR845N v4 0

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Carlos Trujillo
.