Zip Slip Vulnerability in TP-Link WebUI ISP Upgrade Functionality
CVE-2026-12339

6.9MEDIUM

What is CVE-2026-12339?

The vulnerability in TP-Link's WebUI ISP upgrade functionality allows for arbitrary file writes by exploiting crafted ZIP archives containing directory traversal sequences. This weakness can be leveraged by an authenticated administrator to overwrite sensitive files on the underlying system, potentially compromising system integrity and availability. It is crucial for users to apply the necessary patches to mitigate this risk.

Affected Version(s)

Archer MR200 v7 0

Archer MR600 v2 0

TL-MR6400 v5.3 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MrBruh
.