PT-2026-69892 · Tp Link Systems · Archer Mr200 V7+5

·

CVE-2026-12339

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v4.0

6.9

Medium

VectorAV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions WebUI ISP (affected versions not specified)
Description A Zip Slip issue exists in the ISP Upgrade functionality of the WebUI. This occurs when the system fails to properly validate archives, allowing an authenticated administrator to perform arbitrary file writes via a crafted archive containing directory traversal sequences. Directory traversal is a technique used to access files and directories that are stored outside the web root folder. Successful exploitation can lead to the overwriting of arbitrary files on the underlying system, compromising system integrity and availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12339

Affected Products

Archer Mr200 V7
Archer Mr600 V2
Tl-Mr100 V3.20
Tl-Mr150 V3.20
Tl-Mr6400 V5.3
Tl-Mr6400 V8.0