CVE-2026-12339: Authenticated Arbitrary File Write Vulnerability in multiple devices
A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12339?
CVE-2026-12339 has a risk severity score of 50.
How do I fix CVE-2026-12339?
To fix CVE-2026-12339, ensure that you update the WebUI ISP firmware to the latest available version.
What type of vulnerability is CVE-2026-12339?
CVE-2026-12339 is classified as a Path Traversal vulnerability that allows authenticated arbitrary file writes.
Who can exploit CVE-2026-12339?
Only authenticated administrators can exploit CVE-2026-12339 to overwrite arbitrary files on the system.
What can happen if CVE-2026-12339 is exploited?
If CVE-2026-12339 is exploited, it may lead to overwriting of arbitrary files on the affected system.