GHSA-884r-qm45-3j9gMedium
A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL...
🔗 CVE IDs covered (1)
📋 Description
A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis.
Successful exploitation could result in unauthorized access to privileged functions on affected devices.
🔗 References (11)
- https://nvd.nist.gov/vuln/detail/CVE-2026-12001
- https://www.tp-link.com/en/support/download/archer-c20/v6/#Firmware
- https://www.tp-link.com/en/support/download/archer-mr200/v5/#Firmware
- https://www.tp-link.com/en/support/download/tl-wr845n/#Firmware
- https://www.tp-link.com/in/support/download/archer-c20/v6/#Firmware
- https://www.tp-link.com/in/support/download/archer-mr200/v5/#Firmware
- https://www.tp-link.com/in/support/download/tl-wr845n/#Firmware
- https://www.tp-link.com/in/support/download/tl-wr850n/#Firmware
- https://www.tp-link.com/us/support/download/archer-c20/v6/#Firmware
- https://www.tp-link.com/us/support/faq/5210
- https://github.com/advisories/GHSA-884r-qm45-3j9g