Vulnerability Intelligence Report
Authenticated Arbitrary File Write Vulnerability in multiple devices
CVE-2026-12339
A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to be overwritten on the underlying system, affecting system integrity and availability.
Path Traversal
No Active Exploit Signals
CVSS Base Score
6.9
MEDIUM
EPSS Probability:0.31%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v5.3 | 0 < (EU)_1.10.0 0.9.1 v0001.0 Build 260613 RC.76099n (affected) |
| TP-Link Systems Inc. | Archer MR600 v2 | 0 < (EU)_1.10.0 0.9.1 v0001.0 Build 260618 RC.40417n (affected) |
| TP-Link Systems Inc. | Archer MR200 v7 | 0 < (EU)_1.3.0 0.9.1 v0001.0 Build 260605 Rel.57870n (affected) |
| TP-Link Systems Inc. | TL-MR6400 v8.0 | 0 < (EU)_1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n (affected) |
| TP-Link Systems Inc. | TL-MR150 v3.20 | 0 < (EU)_1.3.0 0.9.1 v0001.0 Build 260720 Rel.59727n (affected) |
| TP-Link Systems Inc. | TL-MR100 v3.20 | 0 < (EU)_1.3.0 0.9.1 v0001.0 Build 260609 Rel.49957n (affected), 0 < 1.1.0 0.9.1 v0001.0 Build 260609 Rel35479n, Customized Software for South Korea KT (affected), 0 < 1.2.0 0.9.1 v0001.0 Build 260609 Rel.36250n, Customized Software for South Korea Telenor (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | TP-Link Systems Inc. · Vendor · USA |
| Reserved | 2026-06-15T15:51:52 |
| Published | 2026-08-10T18:20:50 |
| Last Updated | 2026-08-25T23:31:52 |
Community Chatter & Buzz