Answer in brief
CVE-2026-12001 records a Unknown severity vulnerability in Hardcoded Credential Vulnerability in Multiple TP-Link Router Models. The current sources do not mark it as known exploited. The current feed maps TP-Link Systems Inc./Archer C20 v6 (generic), TP-Link Systems Inc./Archer MR200 v5 (generic), TP Link Systems Inc./TL-WR845N v4 (generic), TP-Link Systems Inc./TL-WR850N v3 (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-12001 records a Unknown severity vulnerability in Hardcoded Credential Vulnerability in Multiple TP-Link Router Models. The current sources do not mark it as known exploited. The current feed maps TP-Link Systems Inc./Archer C20 v6 (generic), TP-Link Systems Inc./Archer MR200 v5 (generic), TP Link Systems Inc./TL-WR845N v4 (generic), TP-Link Systems Inc./TL-WR850N v3 (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps TP-Link Systems Inc./Archer C20 v6 (generic), TP-Link Systems Inc./Archer MR200 v5 (generic), TP Link Systems Inc./TL-WR845N v4 (generic), TP-Link Systems Inc./TL-WR850N v3 (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| TP-Link Systems Inc./Archer C20 v6generic | >=0 <Archer C20(US)_V6_250630 | Archer C20(US)_V6_250630 |
| TP-Link Systems Inc./Archer MR200 v5generic | >=0 <EU_V5.20_1.3.0 Build 260319 | EU_V5.20_1.3.0 Build 260319 |
| TP Link Systems Inc./TL-WR845N v4generic | >=0 <TL-WR845N(UN)_V4_250401 | TL-WR845N(UN)_V4_250401 |
| TP-Link Systems Inc./TL-WR850N v3generic | >=0 <TL-WR850N(IN)_V3.48_3.16.0 Build 260422_2048 | TL-WR850N(IN)_V3.48_3.16.0 Build 260422_2048 |
| TP Link Systems Inc./TL-WR902AC v4generic | >=0 <US_V4_0.9.1 Build 260810 || >=0 <EU_V4_0.9.3 Build 260728 | US_V4_0.9.1 Build 260810, EU_V4_0.9.3 Build 260728 |
Published upstream
Jul 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 11, 2026
A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis. Successful exploitation could result in unauthorized access to privileged functions on affected devices.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps TP-Link Systems Inc./Archer C20 v6 (generic), TP-Link Systems Inc./Archer MR200 v5 (generic), TP Link Systems Inc./TL-WR845N v4 (generic), TP-Link Systems Inc./TL-WR850N v3 (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| TP-Link Systems Inc./Archer C20 v6generic | >=0 <Archer C20(US)_V6_250630 | Archer C20(US)_V6_250630 |
| TP-Link Systems Inc./Archer MR200 v5generic | >=0 <EU_V5.20_1.3.0 Build 260319 | EU_V5.20_1.3.0 Build 260319 |
| TP Link Systems Inc./TL-WR845N v4generic | >=0 <TL-WR845N(UN)_V4_250401 | TL-WR845N(UN)_V4_250401 |
| TP-Link Systems Inc./TL-WR850N v3generic | >=0 <TL-WR850N(IN)_V3.48_3.16.0 Build 260422_2048 | TL-WR850N(IN)_V3.48_3.16.0 Build 260422_2048 |
| TP Link Systems Inc./TL-WR902AC v4generic | >=0 <US_V4_0.9.1 Build 260810 || >=0 <EU_V4_0.9.3 Build 260728 | US_V4_0.9.1 Build 260810, EU_V4_0.9.3 Build 260728 |
Published upstream
Jul 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 11, 2026
A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis. Successful exploitation could result in unauthorized access to privileged functions on affected devices.
Quoted source text, attributed separately from HOL analysis.