What is CVE-2026-12001?
A hardcoded credential vulnerability has been found in the firmware of several TP-Link router models, including TL-WR845N v4 and Archer MR200 v5. Authentication-related data embedded in a firmware password file can be recovered through firmware analysis. Users should apply the relevant security updates for affected devices.
Azərbaycanca: TP-Link-in bir neçə router modelində (TL-WR845N v4, TL-WR850N v3, Archer C20 v6, Archer MR200 v5) firmware daxilində "hardcoded" etimadnaməsi aşkarlanıb. Bu zəiflik autentifikasiya məlumatlarının firmware təhlili ilə əldə edilməsinə imkan verir. İstifadəçilər təsirlənən cihazlar üçün təhlükəsizlik yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-798; shared vendor: TP-Link
FAQ2
Which TP-Link router models are affected by CVE-2026-12001?
This vulnerability affects the TL-WR845N v4, TL-WR850N v3, Archer C20 v6, and Archer MR200 v5 models.
How does CVE-2026-12001 allow the recovery of authentication data?
Authentication-related data embedded in the firmware can be recovered through firmware analysis.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.