Description
A Zip Slip vulnerability in the WebUI ISP
Upgrade functionality allows arbitrary file write via a crafted archive
containing directory traversal sequences. An authenticated administrator may
overwrite arbitrary files on the system.Successful
exploitation may allow arbitrary file to be overwritten on the underlying system, affecting system integrity and availability.
Published: 2026-08-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Zip Slip flaw in the WebUI ISP Upgrade functionality that allows an authenticated administrator to craft a malicious ZIP archive containing directory traversal sequences, resulting in arbitrary file writes on the system. This can compromise the device’s integrity by overwriting critical configuration or binaries, and can lead to availability disruptions if essential files are replaced or removed. The weakness is a classic file‑path traversal (CWE‑22).

Affected Systems

TP‑Link Archer MR200 v7, TP‑Link Archer MR600 v2, TP‑Link TL‑MR100 v3.20, TP‑Link TL‑MR150 v3.20, TP‑Link TL‑MR6400 v5.3, and TP‑Link TL‑MR6400 v8.0 are affected. These models expose the WebUI ISP Upgrade feature with no input validation for archive paths. The issue is present in the firmware versions listed above.

Risk and Exploitability

The CVSS score is 6.9, indicating a moderate severity due to the need for authenticated access and a very low likelihood of exploitation, as shown by the EPSS score of < 1%. The vulnerability is not listed in CISA KEV, indicating no confirmed publicly disclosed exploits. An attacker who gains administrator credentials or can trick a legitimate administrator into uploading a crafted package can execute the exploit. The attack vector is local or remote via the WebUI, requiring network connectivity to the device.

Generated by OpenCVE AI on August 26, 2026 at 04:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to the latest release available from the TP‑Link support website for each affected model; the vendor has addressed the Zip Slip issue in newer firmware versions.
  • Restrict administrative access to the WebUI by limiting exposure to internal networks or changing the default administrator credentials to robust passwords.
  • Disable or block access to the ISP web‑interface upgrade feature if the device is not regularly updated through the WebUI.
  • Monitor the device’s filesystem for unexpected changes to critical configuration or binary files and audit logs for suspicious upload activity.

Generated by OpenCVE AI on August 26, 2026 at 04:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Description A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability. A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to be overwritten on the underlying system, affecting system integrity and availability.

Tue, 25 Aug 2026 21:15:00 +0000


Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link archer Mr200 V07
Tp-link archer Mr600 V2
Tp-link tl-mr6400 V5.3
Vendors & Products Tp-link
Tp-link archer Mr200 V07
Tp-link archer Mr600 V2
Tp-link tl-mr6400 V5.3

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.
Title Authenticated Arbitrary File Write Vulnerability in multiple devices
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Archer Mr200 V07 Archer Mr600 V2 Tl-mr6400 V5.3
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-25T23:31:52.397Z

Reserved: 2026-06-15T15:51:52.827Z

Link: CVE-2026-12339

cve-icon Vulnrichment

Updated: 2026-08-11T14:44:42.664Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-10T19:17:28.500

Modified: 2026-08-26T05:18:05.410

Link: CVE-2026-12339

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T04:45:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')