Unrated severityNVD Advisory· Published Jul 27, 2026· Updated Jul 28, 2026
Hardcoded Credential Vulnerability in Multiple TP-Link Router Models
CVE-2026-12001
Description
A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis.
Successful exploitation could result in unauthorized access to privileged functions on affected devices.
Affected products
4- Range: v5
- Range: v6
Patches
Vulnerability mechanics
References
9- www.tp-link.com/en/support/download/archer-c20/v6/mitrepatch
- www.tp-link.com/en/support/download/archer-mr200/v5/mitrepatch
- www.tp-link.com/en/support/download/tl-wr845n/mitrepatch
- www.tp-link.com/in/support/download/archer-c20/v6/mitrepatch
- www.tp-link.com/in/support/download/archer-mr200/v5/mitrepatch
- www.tp-link.com/in/support/download/tl-wr845n/mitrepatch
- www.tp-link.com/in/support/download/tl-wr850n/mitrepatch
- www.tp-link.com/us/support/download/archer-c20/v6/mitrepatch
- www.tp-link.com/us/support/faq/5210/mitrevendor-advisory
News mentions
0No linked articles in our index yet.