Answer in brief
CVE-2026-12339 records a Unknown severity vulnerability in Authenticated Arbitrary File Write Vulnerability in multiple devices. The current sources do not mark it as known exploited. The current feed maps TP-Link Systems Inc./Archer MR200 v7 (generic), TP-Link Systems Inc./Archer MR600 v2 (generic), TP-Link Systems Inc./TL-MR6400 v5.3 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps TP-Link Systems Inc./Archer MR200 v7 (generic), TP-Link Systems Inc./Archer MR600 v2 (generic), TP-Link Systems Inc./TL-MR6400 v5.3 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| TP-Link Systems Inc./Archer MR200 v7generic | >=0 <(EU)_1.3.0 0.9.1 v0001.0 Build 260605 Rel.57870n | (EU)_1.3.0 0.9.1 v0001.0 Build 260605 Rel.57870n |
| TP-Link Systems Inc./Archer MR600 v2generic | >=0 <(EU)_1.10.0 0.9.1 v0001.0 Build 260618 RC.40417n | (EU)_1.10.0 0.9.1 v0001.0 Build 260618 RC.40417n |
| TP-Link Systems Inc./TL-MR6400 v5.3generic | >=0 <(EU)_1.10.0 0.9.1 v0001.0 Build 260613 RC.76099n | (EU)_1.10.0 0.9.1 v0001.0 Build 260613 RC.76099n |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-12339 records a Unknown severity vulnerability in Authenticated Arbitrary File Write Vulnerability in multiple devices. The current sources do not mark it as known exploited. The current feed maps TP-Link Systems Inc./Archer MR200 v7 (generic), TP-Link Systems Inc./Archer MR600 v2 (generic), TP-Link Systems Inc./TL-MR6400 v5.3 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps TP-Link Systems Inc./Archer MR200 v7 (generic), TP-Link Systems Inc./Archer MR600 v2 (generic), TP-Link Systems Inc./TL-MR6400 v5.3 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| TP-Link Systems Inc./Archer MR200 v7generic | >=0 <(EU)_1.3.0 0.9.1 v0001.0 Build 260605 Rel.57870n | (EU)_1.3.0 0.9.1 v0001.0 Build 260605 Rel.57870n |
| TP-Link Systems Inc./Archer MR600 v2generic | >=0 <(EU)_1.10.0 0.9.1 v0001.0 Build 260618 RC.40417n | (EU)_1.10.0 0.9.1 v0001.0 Build 260618 RC.40417n |
| TP-Link Systems Inc./TL-MR6400 v5.3generic | >=0 <(EU)_1.10.0 0.9.1 v0001.0 Build 260613 RC.76099n | (EU)_1.10.0 0.9.1 v0001.0 Build 260613 RC.76099n |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.
Quoted source text, attributed separately from HOL analysis.