Click to skip the navigation bar

Security Advisory: Hardcoded Credential Vulnerability in Multiple TP-Link Router Models (CVE-2026-12001)

Security Advisory
Last updated: July 27, 2026

Vulnerability and Impact Description:

CVE-2026-12001

A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers. Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis.

Successful exploitation could result in unauthorized access to privileged functions on affected devices.

CVSS v4.0 Score: 5.2 /Medium

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products/Versions and Fixes:

Product Model

Hardware Version

Fixed Firmware Version

TL-WR845N

V4

TL-WR845N(UN)_V4_250401

TL-WR850N

V3

TL-WR850N(IN)_V3.48_3.16.0 Build 260422_2048

Archer C20

V6

Archer C20(US)_V6_250630

Archer MR200

V5

Archer MR200(EU)_V5.20_1.3.0 Build 260319

Recommendations:

We strongly recommend that users with affected devices take the following actions:

  1. Update affected devices to the latest firmware version that fixed the vulnerability:

EN: Download for TL-WR845N | TP-Link

Download for Archer C20 | TP-Link

Download for Archer MR200 | TP-Link

US: Download for Archer C20 | TP-Link

IN: Download for TL-WR845N | TP-Link India

Download for TL-WR850N | TP-Link India

Download for Archer C20 | TP-Link India

Download for Archer MR200 | TP-Link India

Note: TL-WR845N, TL-WR850N and Archer MR200 are not sold in the US.

Disclaimer:

This advisory is provided for informational purposes only and is subject to change without notice. The information is provided “as is” without warranties of any kind. TP-Link recommends that customers promptly apply available firmware updates or implement documented workarounds as provided in this advisory. Devices/systems that are not updated or mitigated as described may remain vulnerable, and TP-Link disclaims any responsibility or liability for any damages or losses arising from a failure to implement such updates.

Related FAQs

Looking For More

Is this faq useful?

Your feedback helps improve this site.

Community

TP-Link Community

Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.

Visit the Community >