Five TP-Link router models carry login credentials embedded inside their firmware, according to a security advisory TP-Link published on August 11, 2026. The affected models are the TL-WR845N version 4, TL-WR850N version 3, TL-WR902AC version 4, Archer C20 version 6 and Archer MR200 version 5, and the advisory assigns the flaw the identifier CVE-2026-12001.
The advisory dates to August 11, more than eight weeks before publication of this report, and the CVE entry itself predates the advisory by two weeks. The advisory lists patched firmware for every affected model, so what remains is whether owners of these older routers have installed it.
The five models and the dates
TP-Link’s advisory for CVE-2026-12001, hosted on the Omada Networks support site, lists exactly five router models and revisions, and the list is the whole of the affected set: TL-WR845N (V4), TL-WR850N (V3), TL-WR902AC (V4), Archer C20 (V6) and Archer MR200 (V5). It rates the flaw Medium, with a CVSS v4.0 score of 5.2, and it names patched builds for each model, with release dates running from March through August 2026.
The record is older than the advisory. Both OpenCVE and CERT Croatia’s CVE mirror show the identifier published on July 27, 2026, and OpenCVE shows an update on August 11, the day of the advisory.
A password file inside the firmware image
The weakness is the one catalogued as CWE-798, use of hard-coded credentials. MITRE’s definition describes a product that contains a password or cryptographic key written into it, with the consequence that the same credential applies on every installation and can be read out by anyone who obtains the code.
That is the situation the CVE record describes. In the record’s words, authentication-related credential material is embedded within a password file in the firmware image and can be extracted through firmware analysis, which could give unauthorized access to privileged functions. Firmware images are public downloads, so the extraction can happen offline, on a researcher’s or an attacker’s own computer, before a particular router is ever touched, which is the property that separates a hard-coded credential from a weak password that an attacker would have to guess against a live device.
The severity score is moderate for a reason. SentinelOne’s vulnerability database records the CVSS 4.0 vector as physical attack vector, meaning exploitation requires physical or local access to the device under that scoring, and notes that no public exploits were documented. OpenCVE puts the exploitation probability under 1 percent. The same SentinelOne entry cautions that the firmware analysis itself can be done offline from any downloaded image, which is why the credential’s existence matters even when the scoring is mild.
What an attacker could do with a working credential is the reason the entry exists. SentinelOne’s summary lists DNS tampering, firewall rule changes and persistent compromise as the potential outcomes, and OpenCVE’s entry describes administrative privileges that would permit unauthorized configuration changes and monitoring of network traffic. Those are descriptions of what the credential could unlock on a vulnerable router, not reports of attacks, and neither entry documents any exploitation in the wild.
Firmware builds and the patch
TP-Link’s remedy is the firmware update. The advisory tells owners to promptly apply available updates from the support pages for their model and region, with separate download routes for the United States, the European Union and India. Several of the models are regional: the advisory notes that the TL-WR845N, TL-WR850N and Archer MR200 are not sold in the United States, which narrows the American exposure to the remaining two models, though the advisory does not break out sales for the TL-WR902AC.
The United States download page for the Archer C20 V6 lists firmware builds dated May 21, June 12 and August 13, 2026, each described only as improved security. The page does not mention the credential flaw, so an owner has to match the exact model and hardware revision against the advisory’s list and install the newest build for it.
The recommended follow-ups in the CVE entries are routine hardening, listed by OpenCVE and SentinelOne alike: change the administrative password to something unique, limit the management interface to trusted addresses, turn off remote management and keep the router’s firmware current. Those steps reduce what an extracted credential is worth, though they do not remove the credential from the firmware itself.
The advisory is the only place that ties each model to its fixed build, since the download page for the Archer C20 V6 carries the improved-security wording without a CVE reference. That makes the August 11, 2026 notice the document owners need, and its March-through-August build dates show the fixes were rolling out in stages before the public advisory. The notice carries no suggestion that the credential has been used against anyone, and no later revision to it has appeared.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- The second-largest U.S. reservoir just fell to its lowest level ever recorded
- Security experts still urge phone owners to switch off one location-tracking setting
- The FBI warns a new phishing trick can hijack your account without your password
- The NSA says three phone features should be off whenever you aren’t using them