PT-2026-65117 · Tp Link Systems · Archer C20 V6+3

·

CVE-2026-12001

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v4.0

5.2

Medium

VectorAV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, Archer C20 v6 & Archer MR200 v5).  Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis.
Successful exploitation could result in unauthorized access to privileged functions on affected devices.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12001

Affected Products

Archer C20 V6
Archer Mr200 V5
Tl-Wr845N V4
Tl-Wr850N V3