CVE-2026-12001

MEDIUMCVSS 5.2/10EPSS 0.24%

Last modified

CVE-2026-12001 is a medium-severity vulnerability rated 5.2/10 on the CVSS scale. A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5).  Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis. Successful exploitation could result in unauthorized access to privileged functions on affected devices.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.

Description

A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5).  Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis. Successful exploitation could result in unauthorized access to privileged functions on affected devices.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
TP-Link Systems Inc.TL-WR850N v3< TL-WR850N(IN)_V3.48_3.16.0 Build 260422_2048
TP-Link Systems Inc.Archer C20 v6< Archer C20(US)_V6_250630
TP Link Systems Inc.TL-WR845N v4< TL-WR845N(UN)_V4_250401
TP-Link Systems Inc.Archer MR200 v5< Archer MR200(EU)_V5.20_1.3.0 Build 260319

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2026-12001?
A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5).  Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis. Successful exploitation could result in unauthorized access to privileged functions on affected devices.
How severe is CVE-2026-12001?
CVE-2026-12001 has a CVSS score of 5.2/10 (MEDIUM severity). The EPSS model estimates a 0.24% probability of exploitation in the next 30 days.
How do I fix CVE-2026-12001?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-12001?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST