Junglewise Threat Intelligence

CVE-2026-12339: TP-Link Archer MR router ISP upgrade Zip Slip arbitrary file write

CVE-2026-12339 · Severity: info · Published 2026-08-10

Technologies: TP-Link Archer MR600. Vendors: TP-Link.

Executive brief

TP-Link Archer MR routers provide 4G/LTE connectivity and Wi-Fi for home and business networks. The web-based ISP file upgrade feature is vulnerable to a Zip Slip attack, allowing an authenticated administrator to upload a specially crafted archive that overwrites arbitrary files on the device, compromising system integrity and availability.

Technical details

A Zip Slip vulnerability exists in the WebUI ISP upgrade functionality that fails to properly validate directory traversal sequences in archive entries. An authenticated administrator can craft a malicious ZIP file containing paths with traversal sequences (e.g., ../../../etc/config) to write files outside the intended extraction directory. The vulnerability is exploitable only by authenticated users with administrator access to the web interface. Successful exploitation allows overwriting critical system files, potentially leading to configuration tampering, service disruption, or system compromise. No patch information is currently available in the advisory.

Affected products

  • TP-Link Archer MR200 multiple versions including V5, V6, V7
  • TP-Link Archer MR600 multiple versions including V2, V3, V5

Timeline

  • 2026-08-10: disclosed

References

Related threats