CVE-2026-12339 PUBLISHED

Authenticated Arbitrary File Write Vulnerability in multiple devices

Assigner: TPLink
Reserved: 15.06.2026 Published: 10.08.2026 Updated: 10.08.2026

A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor TP-Link Systems Inc.
Product TL-MR6400 v5.3
Versions Default: unaffected
  • affected from 0 to (EU)_1.10.0 0.9.1 v0001.0 Build 260613 RC.76099n (excl.)
Vendor TP-Link Systems Inc.
Product Archer MR600 v2
Versions Default: unaffected
  • affected from 0 to (EU)_1.10.0 0.9.1 v0001.0 Build 260618 RC.40417n (excl.)
Vendor TP-Link Systems Inc.
Product Archer MR200 v7
Versions Default: unaffected
  • affected from 0 to (EU)_1.3.0 0.9.1 v0001.0 Build 260605 Rel.57870n (excl.)

Credits

  • MrBruh finder

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE

Impacts

  • CAPEC-17 Using Malicious Files