VYPR

AX10

by TP-Link

CVEs (6)

  • CVE-2025-9961HigSep 6, 2025
    risk 0.57cvss epss 0.10

    An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.  The exploit can only be conducted via a Man-In-The-Middle (MITM) attack.  This issue affects AX10 V1/V1.2/V2/V2.6/V3/V3.6: before 1.2.1; AX1500…

  • CVE-2022-41541HigOct 18, 2022
    risk 0.53cvss 8.1epss 0.01

    TP-Link AX10v1 V1_211117 allows attackers to execute a replay attack by using a previously transmitted encrypted authentication message and valid authentication token. Attackers are able to login to the web application as an admin user.

  • CVE-2021-41451HigDec 17, 2021
    risk 0.49cvss 7.5epss 0.02

    A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send a specially crafted HTTP request and receive a misconfigured HTTP/0.9 response, potentially leading into a cache poisoning attack.

  • CVE-2021-41450HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.02

    An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.

  • CVE-2021-40288HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.02

    A denial-of-service attack in WPA2, and WPA3-SAE authentication methods in TP-Link AX10v1 before V1_211014, allows a remote unauthenticated attacker to disconnect an already connected wireless client via sending with a wireless adapter specific spoofed authentication frames

  • CVE-2022-41540MedOct 18, 2022
    risk 0.38cvss 5.9epss 0.01

    The web app client of TP-Link AX10v1 V1_211117 uses hard-coded cryptographic keys when communicating with the router. Attackers who are able to intercept the communications between the web client and router through a man-in-the-middle attack can then obtain the sequence key via…