A Zip Slip vulnerability in the WebUI ISP
Upgrade functionality allows arbitrary file write via a crafted archive
containing directory traversal sequences. An authenticated administrator may
overwrite arbitrary files on the system.Successful
exploitation may allow arbitrary file to be overwritten on the underlying system, affecting system integrity and availability.

Project Subscriptions

Vendors Products
Tp-link Subscribe
Archer Mr200 V07 Subscribe
Archer Mr600 V2 Subscribe
Tl-mr6400 V5.3 Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Description A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability. A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to be overwritten on the underlying system, affecting system integrity and availability.

Tue, 25 Aug 2026 21:15:00 +0000


Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link archer Mr200 V07
Tp-link archer Mr600 V2
Tp-link tl-mr6400 V5.3
Vendors & Products Tp-link
Tp-link archer Mr200 V07
Tp-link archer Mr600 V2
Tp-link tl-mr6400 V5.3

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.
Title Authenticated Arbitrary File Write Vulnerability in multiple devices
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-25T23:31:52.397Z

Reserved: 2026-06-15T15:51:52.827Z

Link: CVE-2026-12339

cve-icon Vulnrichment

Updated: 2026-08-11T14:44:42.664Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-10T19:17:28.500

Modified: 2026-08-26T05:18:05.410

Link: CVE-2026-12339

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T04:45:05Z

Weaknesses