CVE-2026-4346 Details
Description
The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of the device’s flash memory while the serial interface remains enabled and protected by weak authentication. An attacker with physical access and the ability to connect to the serial port can recover sensitive information, including the router’s management password and wireless network key. Successful exploitation can lead to full administrative control of the device and unauthorized access to the associated wireless network.
A vulnerability in the TP-Link TL-WR850N V3 router allows for the cleartext storage of administrative and Wi-Fi credentials in a portion of the device's flash memory. This issue arises while the serial interface is enabled and secured by weak authentication. An attacker with physical access and the ability to connect to the serial port can retrieve sensitive information, including the router's management password and wireless network key. Exploitation of this vulnerability could result in full administrative control of the device and unauthorized access to the associated wireless network.
Users are advised to download and update to the latest firmware version. The latest firmware for TL-WR850N V3 can be downloaded from the TP-Link India support page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/in/support/download/tl-wr850n/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5034/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link tl-wr850n firmware | < 0.9.1_Build251205 |
CPE
Remediation
| |
| tp-link tl-wr850n | 3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | New CVE Received | TPLink |