Description
A Zip Slip vulnerability in the WebUI ISP
Upgrade functionality allows arbitrary file write via a crafted archive
containing directory traversal sequences. An authenticated administrator may
overwrite arbitrary files on the system.Successful
exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.
Published: 2026-08-10
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Zip Slip flaw in the WebUI ISP Upgrade functionality that allows an authenticated administrator to craft a malicious ZIP archive containing directory traversal sequences, resulting in arbitrary file writes on the system. This can compromise the device’s integrity by overwriting critical configuration or binaries, and can lead to availability disruptions if essential files are replaced or removed. The weakness is a classic file‑path traversal (CWE‑22).

Affected Systems

TP‑Link Archer MR200 v7, TP‑Link Archer MR600 v2, and TP‑Link TL‑MR6400 v5.3 are affected. These models expose the WebUI ISP Upgrade feature with no input validation for archive paths. The issue is present in the firmware versions listed above.

Risk and Exploitability

The CVSS score is 6.9, indicating a moderate severity due to the need for authenticated access and lack of public exploitation evidence (EPSS not available). The vulnerability is not listed in CISA KEV, showing no confirmed publicly disclosed exploits. An attacker who gains administrator credentials or can trick a legitimate administrator into uploading a crafted package can execute the exploit. The attack vector is local or remote via the WebUI, requiring network connectivity to the device.

Generated by OpenCVE AI on August 10, 2026 at 19:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to the latest release available from the TP‑Link support website for each affected model; the vendor has addressed the Zip Slip issue in newer firmware versions.
  • Restrict administrative access to the WebUI by limiting exposure to internal networks or changing the default administrator credentials to robust passwords.
  • Disable or block access to the ISP web‑interface upgrade feature if the device is not regularly updated through the WebUI.
  • Monitor the device’s filesystem for unexpected changes to critical configuration or binary files and audit logs for suspicious upload activity.

Generated by OpenCVE AI on August 10, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.
Title Authenticated Arbitrary File Write Vulnerability in multiple devices
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-10T18:20:50.576Z

Reserved: 2026-06-15T15:51:52.827Z

Link: CVE-2026-12339

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T19:30:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')