๐Ÿ” CVE Alert

CVE-2026-12339

UNKNOWN 0.0

Authenticated Arbitrary File Write Vulnerability in multiple devices

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.

CWE CWE-22
Vendor tp-link systems inc.
Product tl-mr6400 v5.3
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for tp-link systems inc. tl-mr6400 v5.3

Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. tl-mr6400 v5.3 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TP-Link Systems Inc. / TL-MR6400 v5.3
0 < (EU)_1.10.0 0.9.1 v0001.0 Build 260613 RC.76099n
TP-Link Systems Inc. / Archer MR600 v2
0 < (EU)_1.10.0 0.9.1 v0001.0 Build 260618 RC.40417n
TP-Link Systems Inc. / Archer MR200 v7
0 < (EU)_1.3.0 0.9.1 v0001.0 Build 260605 Rel.57870n

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
tp-link.com: https://www.tp-link.com/en/support/download/tl-mr6400/v5.30/#Firmware tp-link.com: https://www.tp-link.com/en/support/download/archer-mr600/v2/#Firmware tp-link.com: https://www.tp-link.com/en/support/download/archer-mr200/v7/#Firmware tp-link.com: https://www.tp-link.com/en/support/faq/5237/

Credits

MrBruh