CVE-2026-12001
Severity CVSS v4.0:
MEDIUM
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
27/07/2026
Last modified:
28/07/2026
Description
A hardcoded credential<br />
vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is<br />
embedded within a password file in the firmware image and may be recovered<br />
through firmware analysis.<br />
<br />
<br />
<br />
<br />
<br />
Successful<br />
exploitation could result in unauthorized access to privileged functions on<br />
affected devices.
Impact
Base Score 4.0
5.20
Severity 4.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://www.tp-link.com/en/support/download/archer-c20/v6/#Firmware
- https://www.tp-link.com/en/support/download/archer-mr200/v5/#Firmware
- https://www.tp-link.com/en/support/download/tl-wr845n/#Firmware
- https://www.tp-link.com/in/support/download/archer-c20/v6/#Firmware
- https://www.tp-link.com/in/support/download/archer-mr200/v5/#Firmware
- https://www.tp-link.com/in/support/download/tl-wr845n/#Firmware
- https://www.tp-link.com/in/support/download/tl-wr850n/#Firmware
- https://www.tp-link.com/us/support/download/archer-c20/v6/#Firmware
- https://www.tp-link.com/us/support/faq/5210/



