Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-12339— Authenticated Arbitrary File Write Vulnerability in multiple devices

Quick assessment

Affected
TP-Link Systems Inc. TL-MR6400 v5.3
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

TP-Link TL-MR6400是中国TP-Link公司开源的一款4G无线路由器。 TP-Link TL-MR6400存在路径遍历漏洞,该漏洞源于WebUI ISP Upgrade功能存在Zip Slip漏洞,通过包含目录遍历序列的特制存档允许任意文件写入,可能导致经过身份验证的管理员覆盖系统上的任意文件,影响系统完整性和可用性。

CVSS 6.9 · Medium EPSS 0.53% · P42

Affected Version Matrix 8

VendorProduct Version RangeStatus
TP-Link Systems Inc. Archer MR200 v7 < (EU)_1.3.0 0.9.1 v0001.0 Build 260605 Rel.57870n affected
TP-Link Systems Inc. Archer MR600 v2 < (EU)_1.10.0 0.9.1 v0001.0 Build 260618 RC.40417n affected
TP-Link Systems Inc. TL-MR100 v3.20 < (EU)_1.3.0 0.9.1 v0001.0 Build 260609 Rel.49957n affected
< 1.1.0 0.9.1 v0001.0 Build 260609 Rel35479n,  Customized Software for South Korea KT affected
< 1.2.0 0.9.1 v0001.0 Build 260609 Rel.36250n, Customized Software for South Korea Telenor affected
TP-Link Systems Inc. TL-MR150 v3.20 < (EU)_1.3.0 0.9.1 v0001.0 Build 260720 Rel.59727n affected
TP-Link Systems Inc. TL-MR6400 v5.3 < (EU)_1.10.0 0.9.1 v0001.0 Build 260613 RC.76099n affected
TP-Link Systems Inc. TL-MR6400 v8.0 < (EU)_1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-12339

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Authenticated Arbitrary File Write Vulnerability in multiple devices
Source: CVE Program / CVE List V5
Vulnerability Description
A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to be overwritten on the underlying system, affecting system integrity and availability.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5
Vulnerability Title
TP-Link TL-MR6400 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
TP-Link TL-MR6400是中国TP-Link公司开源的一款4G无线路由器。 TP-Link TL-MR6400存在路径遍历漏洞,该漏洞源于WebUI ISP Upgrade功能存在Zip Slip漏洞,通过包含目录遍历序列的特制存档允许任意文件写入,可能导致经过身份验证的管理员覆盖系统上的任意文件,影响系统完整性和可用性。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
TP-Link Systems Inc. TL-MR6400 v5.3 0 ~ (EU)_1.10.0 0.9.1 v0001.0 Build 260613 RC.76099n -
TP-Link Systems Inc. Archer MR600 v2 0 ~ (EU)_1.10.0 0.9.1 v0001.0 Build 260618 RC.40417n -
TP-Link Systems Inc. Archer MR200 v7 0 ~ (EU)_1.3.0 0.9.1 v0001.0 Build 260605 Rel.57870n -
TP-Link Systems Inc. TL-MR6400 v8.0 0 ~ (EU)_1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n -
TP-Link Systems Inc. TL-MR150 v3.20 0 ~ (EU)_1.3.0 0.9.1 v0001.0 Build 260720 Rel.59727n -
TP-Link Systems Inc. TL-MR100 v3.20 0 ~ (EU)_1.3.0 0.9.1 v0001.0 Build 260609 Rel.49957n -

II. Public POCs for CVE-2026-12339

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12339

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-12339 (1)

Vendor Pages for CVE-2026-12339 (7)

Same Patch Batch · TP-Link Systems Inc. · 2026-08-10 · 6 CVEs total

CVE-2025-30237 8.7 HIGH Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet D
CVE-2025-30241 8.6 HIGH OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices
CVE-2025-30238 8.6 HIGH Privilege Escalation via Improper Authorization in User Management in multiple TP-Link Agi
CVE-2025-30239 8.5 HIGH Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet Dev
CVE-2025-30240 5.1 MEDIUM Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP-

IV. Related Vulnerabilities

V. Comments for CVE-2026-12339

No comments yet


Leave a comment