Junglewise Threat Intelligence

CVE-2026-12001: TP-Link Multiple Routers hardcoded credentials in firmware

CVE-2026-12001 · Severity: info · CVSS 5.2 · Published 2026-07-27

Vendors: TP-Link.

Executive brief

A security vulnerability exists in several TP-Link router models where sensitive login credentials are permanently stored within the device's internal software. An individual with physical access to the device or its software files could extract these credentials to gain unauthorized access to restricted management settings. This could allow an attacker to modify network configurations or disrupt the device's operation.

Technical details

A hardcoded credential vulnerability (CWE-798) exists in the firmware of multiple TP-Link router models, including the TL-WR845N, TL-WR850N, Archer C20, and Archer MR200. Authentication-related material is embedded within a password file in the firmware image. An attacker can recover these credentials through firmware analysis, which typically requires physical access to the device or obtaining the firmware image. Successful exploitation allows the attacker to bypass standard authentication and access privileged management functions. TP-Link has released updated firmware versions to address this issue.

Affected products

  • TP-Link TL-WR845N v4 Before TL-WR845N(UN)_V4_250401
  • TP-Link TL-WR845N v3 Before TL-WR845N(IN)_V3.48_3.16.0 Build 260422_2048
  • TP-Link Archer C20 v6 Before Archer C20(US)_V6_250630
  • TP-Link Archer MR200 v5 Before Archer MR200(EU)_V5.20_1.3.0 Build 260319

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: advisory

References

Related threats