A hardcoded credential
vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is
embedded within a password file in the firmware image and may be recovered
through firmware analysis.
Successful
exploitation could result in unauthorized access to privileged functions on
affected devices.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link archer C20 V6 Tp-link archer Mr200 V5 Tp-link tl-wr845n V4 Tp-link tl-wr850n V3 |
|
| Vendors & Products |
Tp-link
Tp-link archer C20 V6 Tp-link archer Mr200 V5 Tp-link tl-wr845n V4 Tp-link tl-wr850n V3 |
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis. Successful exploitation could result in unauthorized access to privileged functions on affected devices. | |
| Title | Hardcoded Credential Vulnerability in Multiple TP-Link Router Models | |
| Weaknesses | CWE-798 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published: 2026-07-27T20:08:50.230Z
Updated: 2026-07-28T20:49:43.134Z
Reserved: 2026-06-11T16:23:35.413Z
Link: CVE-2026-12001
Updated: 2026-07-28T15:09:08.419Z
No data.
No data.