CVE-2026-4346Disclosure(tp-link / tl-wr850n)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tp-link tl-wr850n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of the device’s flash memory while the serial interface remains enabled and protected by weak authentication. An attacker with physical access and the ability to connect to the serial port can recover sensitive information, including the router’s management password and wireless network key. Successful exploitation can lead to full administrative control of the device and unauthorized access to the associated wireless network.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-312

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tl-wr850n
  • tl-wr850n_firmware

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-26); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
tl-wr850ntl-wr850n_firmware

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-26: 1Mentions · 2026-03-27: 1Mentions · 2026-05-26: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 103-2603-2705-26
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-261
Disclosure1
2026-03-271
Patch1
2026-05-261
Disclosure1
Full discourse3 posts
  • Muqsit 𝕏@mqst_
    Disclosure

    💻 How a Discarded Device Exposed WiFi Credentials and Web Admin Credentials (CVE-2026-4346) Blog: https://securityspace2.wordpress.com/2026/04/06/how-a-discarded-device-exposed-wifi-credentials-and-admin-access-cve-2026-4346/ Author: Cyber coyote https://t.co/2VNeccfIGQ

    Post summary

    Blog post announcing CVE‑2026‑4346 that caused a discarded device to expose Wi‑Fi and web admin credentials, without providing exploitation details or patches.

    1240106427.4K
    12.8K followersView on X
  • NerdieNews@NewsNerdie
    Patch

    A vulnerability in TP Link's TL-WR850N (CVE-2026-4346) allows attackers to access cleartext admin and Wi-Fi credentials via the serial interface. Update firmware immediately to secure your network. #CyberSecurity #InfoSec https://t.co/KNlXCF7IqE

    Post summary

    The tweet announces a credential disclosure flaw in TP‑Link TL‑WR850N (CVE‑2026‑4346) that can be mitigated by updating firmware immediately.

    0000039
    53 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4346 The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of the device’s flash memory while the serial inte… https://www.cve.org/CVERecord?id=CVE-2026-4346

    Post summary

    The article notes that TL‑WR850N v3 stores admin and Wi‑Fi credentials in cleartext on flash memory, describing the vulnerability but providing no exploits, PoC, or remediation.

    0000056
    56.9K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linktl-wr850n3--
OStp-linktl-wr850n_firmware---

Explore more