VYPR

TL-WR902AC

by TP-Link

CVEs (6)

  • CVE-2022-25074CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.13

    TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.

  • CVE-2022-48194HigDec 30, 2022
    risk 0.63cvss 8.8epss 0.33

    TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.

  • CVE-2023-36489HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.00

    Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: TL-WR802N firmware versions prior to 'TL-WR802N(JP)_V4_221008', TL-WR841N firmware versions prior to…

  • CVE-2023-50225MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.01

    TP-Link TL-WR902AC dm_fillObjByStr Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR902AC routers. Authentication is required to exploit this…

  • CVE-2023-44447MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    TP-Link TL-WR902AC loginFs Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR902AC routers. Authentication is not required to exploit this…

  • CVE-2026-12001MedJul 27, 2026
    risk 0.34cvss epss 0.00

    A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5).  Authentication-related credential material is embedded within a password file in the firmware image and may be…