CVE-2026-12339
Authenticated Arbitrary File Write Vulnerability in multiple devices
No known exploitation. EPSS puts it in the 42nd percentile. No fix published yet.
What to do
No fixed build or workaround is published yet. Limit exposure and watch for a patch.
What it is
From the CVE record
A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.
In plain language
No plain-language summary for this CVE yet.
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Not in the catalog. CISA has not confirmed exploitation.
- Public exploits
No public exploit or proof of concept found in the sources we track.
- EPSS
0.5% chance of exploitation activity in the next 30 days, which ranks it in the 42nd percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
7 events over 15 days, from the signal feeds we watch.
- Record updated
- Record updated
- Record updated
- Publishedweakness classified, att&ck mapped, record updated
Affected products
- TL-MR6400 v5.3Networking Infrastructure
- Archer MR600 v2Networking Infrastructure / router-switch
- Archer MR200 v7Networking Infrastructure / router-switch
- TL-MR6400 v8.0Networking Infrastructure / router-switch
- TL-MR150 v3.20Networking Infrastructure / router-switch
- TL-MR100 v3.20Networking Infrastructure / router-switch
Technical detail
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
Sources
References in the record
- tp-link.com/en/support/download/archer-mr200/v7/
- tp-link.com/en/support/download/archer-mr600/v2/
- tp-link.com/en/support/download/tl-mr100/v3.20/
And 5 more references. See all after sign-in
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for TL-MR6400 V5.3, not every advisory.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI