CVE-2026-12001 MEDIUM

CVE-2026-12001: Hardcoded Credential Vulnerability in Multiple TP-Link Router Models

Vendor Tp-Link Systems Inc.
Product TL-WR850N v3
Weakness CWE-798 · Hardcoded credentials
Published July 27, 2026
Last update July 28, 2026

CVSS base score

5.2/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, Archer C20 v6 & Archer MR200 v5).  Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis. Successful exploitation could result in unauthorized access to privileged functions on affected devices.

Key dates

02Disclosure timeline

July 27, 2026 CVE published
July 28, 2026 Record updated

Related vulnerabilities

04Related CVE