CVE Explorer
CVE-2026-4346
The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of the device’s flash memory while the serial interface remains enabled and protected by weak authentication. An attacker with physical access and the ability to connect to the serial port can recover sensitive information, including the router’s management password and wireless network key.
Successful exploitation can lead to full administrative control of the device and unaut
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"TL-WR850N v3","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"V3_0.9.1 Build251205","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:89a2554eaa1374d3da5c5ee7a8f1cc816ac8a08be11e04518b234af510d0f86d · sha256:8b918cb038eb5783… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"PHYSICAL","baseScore":5.1,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:P/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:89a2554eaa1374d3da5c5ee7a8f1cc816ac8a08be11e04518b234af510d0f86d · sha256:8b918cb038eb5783… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-312","description":"CWE-312 Cleartext storage of sensitive information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:89a2554eaa1374d3da5c5ee7a8f1cc816ac8a08be11e04518b234af510d0f86d · sha256:8b918cb038eb5783… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["patch"],"url":"https://www.tp-link.com/in/support/download/tl-wr850n/#Firmware"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:89a2554eaa1374d3da5c5ee7a8f1cc816ac8a08be11e04518b234af510d0f86d · sha256:8b918cb038eb5783… · /containers/cna/references/0
{"tags":["vendor-advisory"],"url":"https://www.tp-link.com/us/support/faq/5034/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:89a2554eaa1374d3da5c5ee7a8f1cc816ac8a08be11e04518b234af510d0f86d · sha256:8b918cb038eb5783… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.