VYPR

Vendor CVEs

TP-Link

All CVEs

614 total · sorted by risk
  • CVE-2024-12343MedDec 8, 2024
    risk 0.43cvss 6.5epss 0.05

    A vulnerability classified as critical has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected is an unknown function of the file /control/WANIPConnection of the component SOAP Request Handler. The manipulation of the argument NewConnectionType leads to buffer overflow.…

  • CVE-2021-44864MedFeb 8, 2022
    risk 0.43cvss 6.5epss 0.10

    TP-Link WR886N 3.0 1.0.1 Build 150127 Rel.34123n is vulnerable to Buffer Overflow. Authenticated attackers can crash router httpd services via /userRpm/PingIframeRpm.htm request which contains redundant & in parameter.

  • CVE-2019-19143MedJan 27, 2020
    risk 0.43cvss 6.1epss 0.07

    TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI.

  • CVE-2018-13134MedJul 4, 2018
    risk 0.43cvss 6.1epss 0.02

    TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI.

  • CVE-2017-15291MedOct 20, 2017
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject arbitrary web script or HTML via the Description field.

  • CVE-2025-9291MedAug 3, 2026
    risk 0.42cvss 6.5epss 0.00

    A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow…

  • CVE-2026-13230MedJul 15, 2026
    risk 0.42cvss 6.5epss 0.00

    An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve…

  • CVE-2026-12760MedJun 24, 2026
    risk 0.42cvss 6.5epss 0.00

    A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets.  An unauthenticated adjacent attacker can send crafted packets to cause excessive resource consumption, leading…

  • CVE-2026-1871MedJun 2, 2026
    risk 0.42cvss 6.5epss 0.00

    TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core…

  • CVE-2026-34124MedApr 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The implementation enforces length restrictions on the raw request path but does not account for path expansion performed during normalization. An attacker…

  • CVE-2026-34122MedApr 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling component due to insufficient input validation. An attacker can exploit this vulnerability by supplying an excessively long value for a vulnerable…

  • CVE-2026-34120MedApr 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing of local video stream content due to insufficient alignment and validation of buffer boundaries when processing streaming inputs.An attacker on the same network…

  • CVE-2026-34119MedApr 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when appending segmented request bodies without continuous write‑boundary verification, due to insufficient boundary validation when handling externally supplied…

  • CVE-2026-34118MedApr 2, 2026
    risk 0.42cvss 6.5epss 0.01

    A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to insufficient boundary validation when handling…

  • CVE-2025-7375MedMar 5, 2026
    risk 0.42cvss 6.5epss 0.00

    A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can send crafted requests to cause the device’s HTTP service to crash. This results in temporary service unavailability until the device is rebooted. This…

  • CVE-2026-0653MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.00

    On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchronization endpoint. This allows modification of protected device settings despite limited privileges. An attacker may change…

  • CVE-2025-15548MedJan 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application layer encryption, allowing a network adjacent attacker to intercept this traffic and compromise its confidentiality.

  • CVE-2025-9521MedJan 26, 2026
    risk 0.42cvss 6.5epss 0.00

    Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to weakened account security.

  • CVE-2025-14631MedJan 7, 2026
    risk 0.42cvss 6.5epss 0.00

    A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows  an adjacent attacker to cause a denial-of-service (DoS) by triggering a device reboot. This issue affects Archer BE400: xi 1.1.0 Build 20250710 rel.14914.

  • CVE-2025-14175MedDec 29, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and decrypt SSH traffic. Exploitation may expose sensitive information and compromise confidentiality.

  • CVE-2025-8065MedDec 20, 2025
    risk 0.42cvss 6.5epss 0.01

    A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer. It allowed a…

  • CVE-2025-14299MedDec 20, 2025
    risk 0.42cvss 6.5epss 0.00

    The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests to trigger excessive memory allocation, causing the device…

  • CVE-2024-48714MedOct 15, 2024
    risk 0.42cvss 6.5epss 0.00

    In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

  • CVE-2024-48713MedOct 15, 2024
    risk 0.42cvss 6.5epss 0.00

    In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

  • CVE-2024-48712MedOct 15, 2024
    risk 0.42cvss 6.5epss 0.00

    In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

  • CVE-2024-48710MedOct 15, 2024
    risk 0.42cvss 6.5epss 0.00

    In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

  • CVE-2024-9284MedSep 27, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in TP-LINK TL-WR841ND up to 20240920. It has been rated as critical. Affected by this issue is some unknown functionality of the file /userRpm/popupSiteSurveyRpm.htm. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack…

  • CVE-2023-44447MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    TP-Link TL-WR902AC loginFs Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR902AC routers. Authentication is not required to exploit this…

  • CVE-2023-34829MedDec 28, 2023
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.

  • CVE-2023-39610MedOct 31, 2023
    risk 0.42cvss 6.5epss 0.00

    An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted web request.

  • CVE-2023-38909MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the IV component in the AES128-CBC function.

  • CVE-2023-38908MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the TSKEP authentication function.

  • CVE-2023-38906MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue in TPLink Smart Bulb Tapo series L530 1.1.9, L510E 1.0.8, L630 1.0.3, P100 1.4.9, Smart Camera Tapo series C200 1.1.18, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the authentication code for the UDP message.

  • CVE-2022-43635MedMar 29, 2023
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service,…

  • CVE-2022-24972MedMar 28, 2023
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2023-0936MedFeb 21, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in TP-Link Archer C50 V2_160801. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Web Management Interface. The manipulation leads to denial of service. The attack can only be initiated within the…

  • CVE-2022-41505MedJan 23, 2023
    risk 0.42cvss 6.4epss 0.00

    An access control issue on TP-LInk Tapo C200 V1 devices allows physically proximate attackers to obtain root access by connecting to the UART pins, interrupting the boot process, and setting an init=/bin/sh value.

  • CVE-2022-46139MedDec 20, 2022
    risk 0.42cvss 6.5epss 0.00

    TP-Link TL-WR940N V4 3.16.9 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.

  • CVE-2022-4296MedDec 6, 2022
    risk 0.42cvss 6.5epss 0.00

    A vulnerability classified as problematic has been found in TP-Link TL-WR740N. Affected is an unknown function of the component ARP Handler. The manipulation leads to resource consumption. The attack needs to be done within the local network. The exploit has been disclosed to…

  • CVE-2021-29280MedAug 19, 2021
    risk 0.42cvss 6.4epss 0.01

    In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow

  • CVE-2021-27210MedFeb 13, 2021
    risk 0.42cvss 6.5epss 0.01

    TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,0#0,0,0,0,0,0]0,0 to the /cgi?1&5 URI.

  • CVE-2020-28005MedNov 18, 2020
    risk 0.42cvss 6.5epss 0.02

    httpd on TP-Link TL-WPA4220 devices (hardware versions 2 through 4) allows remote authenticated users to trigger a buffer overflow (causing a denial of service) by sending a POST request to the /admin/syslog endpoint. Fixed version: TL-WPA4220(EU)_V4_201023

  • CVE-2020-15057MedAug 7, 2020
    risk 0.42cvss 6.5epss 0.00

    TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to denial-of-service the device via long input values.

  • CVE-2018-15701MedOct 1, 2018
    risk 0.42cvss 6.5epss 0.01

    The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated LAN user sends a crafted HTTP header containing an unexpected Cookie field.

  • CVE-2018-15700MedOct 1, 2018
    risk 0.42cvss 6.5epss 0.01

    The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated LAN user sends a crafted HTTP header containing an unexpected Referer field.

  • CVE-2018-17018MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for time_switch name.

  • CVE-2018-17017MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for dhcpd udhcpd enable.

  • CVE-2018-17016MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for reboot_timer name.

  • CVE-2018-17015MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for ddns phddns username.

  • CVE-2018-17014MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for ip_mac_bind name.

Page 10 of 13