Upgrade functionality allows arbitrary file write via a crafted archive
containing directory traversal sequences. An authenticated administrator may
overwrite arbitrary files on the system.Successful
exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link archer Mr200 V07 Tp-link archer Mr600 V2 Tp-link tl-mr6400 V5.3 |
|
| Vendors & Products |
Tp-link
Tp-link archer Mr200 V07 Tp-link archer Mr600 V2 Tp-link tl-mr6400 V5.3 |
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability. | |
| Title | Authenticated Arbitrary File Write Vulnerability in multiple devices | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-08-11T14:44:53.124Z
Reserved: 2026-06-15T15:51:52.827Z
Link: CVE-2026-12339
Updated: 2026-08-11T14:44:42.664Z
Status : Received
Published: 2026-08-10T19:17:28.500
Modified: 2026-08-11T15:17:27.297
Link: CVE-2026-12339
No data.
OpenCVE Enrichment
Updated: 2026-08-11T14:22:13Z