Refine your search
1 vulnerability found for Archer MR600 v2 by TP-Link Systems Inc.
CVE-2026-12339 (GCVE-0-2026-12339)
Vulnerability from cvelistv5
Published
2026-08-10 18:20
Modified
2026-08-25 23:31
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Summary
A Zip Slip vulnerability in the WebUI ISP
Upgrade functionality allows arbitrary file write via a crafted archive
containing directory traversal sequences. An authenticated administrator may
overwrite arbitrary files on the system.Successful
exploitation may allow arbitrary file to be overwritten on the underlying system, affecting system integrity and availability.
References
Impacted products
| Vendor | Product | Version | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v5.3 |
Version: 0 < (EU)_1.10.0 0.9.1 v0001.0 Build 260613 RC.76099n |
|||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-12339",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-11T14:44:35.924185Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-11T14:44:53.124Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "TL-MR6400 v5.3",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(EU)_1.10.0 0.9.1 v0001.0 Build 260613 RC.76099n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Archer MR600 v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(EU)_1.10.0 0.9.1 v0001.0 Build 260618 RC.40417n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Archer MR200 v7",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(EU)_1.3.0 0.9.1 v0001.0 Build 260605 Rel.57870n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "TL-MR6400 v8.0",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(EU)_1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "TL-MR150 v3.20",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(EU)_1.3.0 0.9.1 v0001.0 Build 260720 Rel.59727n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "TL-MR100 v3.20",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(EU)_1.3.0 0.9.1 v0001.0 Build 260609 Rel.49957n",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "1.1.0 0.9.1 v0001.0 Build 260609 Rel35479n, \u00a0Customized Software for South Korea KT",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "1.2.0 0.9.1 v0001.0 Build 260609 Rel.36250n, Customized Software for South Korea Telenor",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "MrBruh"
},
{
"lang": "en",
"type": "finder",
"value": "haehet"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "A Zip Slip vulnerability in the WebUI ISP\nUpgrade functionality allows arbitrary file write via a crafted archive\ncontaining directory traversal sequences. An authenticated administrator may\noverwrite arbitrary files on the system.\u003cdiv\u003eSuccessful\nexploitation may allow arbitrary file to be overwritten on the underlying system, affecting system integrity and availability. \u003c/div\u003e"
}
],
"value": "A Zip Slip vulnerability in the WebUI ISP\nUpgrade functionality allows arbitrary file write via a crafted archive\ncontaining directory traversal sequences. An authenticated administrator may\noverwrite arbitrary files on the system.Successful\nexploitation may allow arbitrary file to be overwritten on the underlying system, affecting system integrity and availability."
}
],
"impacts": [
{
"capecId": "CAPEC-17",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-17 Using Malicious Files"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T23:31:52.397Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-mr6400/v5.30/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-mr600/v2/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-mr200/v7/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/en/support/faq/5237/"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-mr100/v3.20/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-mr150/v3.20/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/kr/support/download/tl-mr100/v3.20/#Firmware"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Authenticated Arbitrary File Write Vulnerability in multiple devices",
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-12339",
"datePublished": "2026-08-10T18:20:50.576Z",
"dateReserved": "2026-06-15T15:51:52.827Z",
"dateUpdated": "2026-08-25T23:31:52.397Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}