CVE-2026-12001: TP-Link Systems Inc Archer c20 v6
Medium severity, CVSS 5.2. EPSS: 0.3% chance of exploitation in the next 30 days.
A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis. Successful exploitation could result in unauthorized access to privileged functions on affected devices.
Affected products
- TP-Link Systems Inc Archer c20 v6
- TP-Link Systems Inc Archer MR200 v5
- TP-Link Systems Inc Tl-WR850N v3
- TP Link Systems Inc Tl-WR845N v4
- TP Link Systems Inc Tl-WR902AC v4
Published 2026-07-27. Last modified 2026-08-11.