CVE-2026-12001

A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5).  Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis. Successful exploitation could result in unauthorized access to privileged functions on affected devices.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-07-27 21:16

Updated : 2026-08-11 21:17


NVD link : CVE-2026-12001

Mitre link : CVE-2026-12001

CVE.ORG link : CVE-2026-12001


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials