VYPR

Vendor CVEs

TP-Link

All CVEs

614 total · sorted by risk
  • CVE-2018-17013MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for protocol wan wan_rate.

  • CVE-2018-17012MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for hosts_info set_block_flag up_limit.

  • CVE-2018-17011MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for hosts_info para sun.

  • CVE-2018-17010MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for wireless wlan_host_2g bandwidth.

  • CVE-2018-17009MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for wireless wlan_host_2g isolate.

  • CVE-2018-17008MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for wireless wlan_host_2g power.

  • CVE-2018-17007MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for wireless wlan_wds_2g ssid.

  • CVE-2018-17006MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for firewall lan_manage mac2.

  • CVE-2018-17005MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for firewall dmz enable.

  • CVE-2018-17004MedSep 13, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for wlan_access name.

  • CVE-2017-17747MedDec 20, 2017
    risk 0.42cvss 6.5epss 0.01

    Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service condition.

  • CVE-2017-16959MedNov 27, 2017
    risk 0.42cvss 6.5epss 0.02

    The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted…

  • CVE-2017-10796MedJul 2, 2017
    risk 0.42cvss 6.5epss 0.01

    On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:554/h264_hd.sdp URL.

  • CVE-2017-8219MedApr 25, 2017
    risk 0.42cvss 6.5epss 0.01

    TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow DoSing the HTTP server via a crafted Cookie header to the /cgi/ansi URI.

  • CVE-2025-15541MedJan 29, 2026
    risk 0.41cvss 6.3epss 0.00

    Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files, resulting in high confidentiality impact and limited integrity risk.

  • CVE-2024-46548MedSep 30, 2024
    risk 0.41cvss 6.3epss 0.00

    TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a man-in-the-middle attack.

  • CVE-2024-37662MedJun 17, 2024
    risk 0.41cvss 6.3epss 0.00

    TP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router.

  • CVE-2024-37661MedJun 17, 2024
    risk 0.41cvss 6.3epss 0.00

    TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.

  • CVE-2026-18330MedSep 3, 2026
    risk 0.40cvss —epss 0.00

    A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt the administrator password; the weakened AES session key further reduces the…

  • CVE-2026-1571MedFeb 11, 2026
    risk 0.40cvss 6.1epss 0.00

    User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbitrary JavaScript execution via a crafted URL. An attacker could run script in the device web UI context, potentially enabling credential theft, session…

  • CVE-2024-2188MedMar 5, 2024
    risk 0.40cvss 6.1epss 0.01

    Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. This vulnerability could allow an unauthenticated attacker to create a port mapping rule via a SOAP request and store a malicious JavaScript payload within…

  • CVE-2022-42202MedOct 18, 2022
    risk 0.40cvss 6.1epss 0.00

    TP-Link TL-WR841N 8.0 4.17.16 Build 120201 Rel.54750n is vulnerable to Cross Site Scripting (XSS).

  • CVE-2020-17891MedMay 14, 2021
    risk 0.40cvss 6.1epss 0.01

    TP-Link Archer C1200 firmware version 1.13 Build 2018/01/24 rel.52299 EU has a XSS vulnerability allowing a remote attacker to execute arbitrary code.

  • CVE-2021-3275MedMar 26, 2021
    risk 0.40cvss 6.1epss 0.02

    Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers), Access Points, ADSL + DSL Gateways and Routers, which affects TD-W9977v1, TL-WA801NDv5, TL-WA801Nv6, TL-WA802Nv5, and Archer C3150v2 devices…

  • CVE-2020-5797MedNov 21, 2020
    risk 0.40cvss 6.1epss 0.01

    UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with physical access and network access, to read sensitive files and write to a limited set of files after plugging a crafted USB drive into the router.

  • CVE-2020-5795MedNov 6, 2020
    risk 0.40cvss 6.2epss 0.01

    UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)_V5_200721 allows an authenticated admin user, with physical access and network access, to execute arbitrary code after plugging a crafted USB drive into the router.

  • CVE-2016-10719MedMay 15, 2019
    risk 0.40cvss 6.1epss 0.01

    TP-Link Archer CR-700 1.0.6 devices have an XSS vulnerability that can be introduced into the admin account through a DHCP request, allowing the attacker to steal the cookie information, which contains the base64 encoded username and password.

  • CVE-2026-0620MedFeb 3, 2026
    risk 0.39cvss —epss 0.00

    When configured as L2TP/IPSec VPN server, Archer AXE75 V1 may accept connections using L2TP without IPSec protection, even when IPSec is enabled.  This allows VPN sessions without encryption, exposing data in transit and compromising confidentiality.

  • CVE-2025-15631MedAug 3, 2026
    risk 0.38cvss 5.9epss 0.00

    A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials…

  • CVE-2025-15630MedAug 3, 2026
    risk 0.38cvss 5.9epss 0.00

    A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. …

  • CVE-2025-15544MedAug 3, 2026
    risk 0.38cvss 5.9epss 0.00

    A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully…

  • CVE-2025-9290MedJan 23, 2026
    risk 0.38cvss 5.9epss 0.00

    An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge…

  • CVE-2022-41540MedOct 18, 2022
    risk 0.38cvss 5.9epss 0.01

    The web app client of TP-Link AX10v1 V1_211117 uses hard-coded cryptographic keys when communicating with the router. Attackers who are able to intercept the communications between the web client and router through a man-in-the-middle attack can then obtain the sequence key via…

  • CVE-2021-38543MedAug 11, 2021
    risk 0.38cvss 5.9epss 0.01

    TP-Link UE330 USB splitter devices through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a…

  • CVE-2026-75619MedAug 19, 2026
    risk 0.37cvss 5.7epss 0.00

    Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bounds heap writes. Successful…

  • CVE-2026-15141MedAug 12, 2026
    risk 0.37cvss 5.7epss 0.00

    The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful…

  • CVE-2026-30817MedApr 8, 2026
    risk 0.37cvss 5.7epss 0.00

    An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary…

  • CVE-2026-30816MedApr 8, 2026
    risk 0.37cvss 5.7epss 0.00

    An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary…

  • CVE-2023-28368MedApr 11, 2023
    risk 0.37cvss 5.7epss 0.00

    TP-Link L2 switch T2600G-28SQ firmware versions prior to 'T2600G-28SQ(UN)_V1_1.0.6 Build 20230227' uses vulnerable SSH host keys. A fake device may be prepared to spoof the affected device with the vulnerable host key.If the administrator may be tricked to login to the fake…

  • CVE-2025-15551MedFeb 5, 2026
    risk 0.36cvss 5.6epss 0.00

    The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is getting executed by the JavaScript function like eval directly without any check. Attackers can exploit this vulnerability via a Man-in-the-Middle (MitM) attack…

  • CVE-2024-46325MedOct 7, 2024
    risk 0.36cvss 5.5epss 0.00

    TP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url.

  • CVE-2022-41783MedDec 7, 2022
    risk 0.36cvss 5.5epss 0.00

    tdpServer of TP-Link RE300 V1 improperly processes its input, which may allow an attacker to cause a denial-of-service (DoS) condition of the product's OneMesh function.

  • CVE-2021-28858MedJun 15, 2021
    risk 0.36cvss 5.5epss 0.00

    TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monitor traffic and capture the cookie and other sensitive information.

  • CVE-2020-12475MedMay 4, 2020
    risk 0.36cvss 5.5epss 0.01

    TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.portal.PortalController.getAdvertiseFile in /opt/tplink/EAPController/lib/eap-web-3.2.6.jar.

  • CVE-2025-25427MedApr 18, 2025
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/v14.8 <= Build 241230 Rel. 50788n allows remote attackers to inject arbitrary JavaScript code via the port mapping description. This leads to an execution of…

  • CVE-2024-4224MedJul 15, 2024
    risk 0.35cvss 5.4epss 0.00

    An authenticated stored cross-site scripting (XSS) exists in the TP-Link TL-SG1016DE affecting version TL-SG1016DE(UN) V7.6_1.0.0 Build 20230616, which could allow an adversary to run JavaScript in an administrator's browser. This issue was fixed in TL-SG1016DE(UN) V7_1.0.1…

  • CVE-2020-11445MedApr 1, 2020
    risk 0.35cvss 5.3epss 0.02

    TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive information via vectors involving a Wi-Fi session with GPS enabled, aka CNVD-2020-04855.

  • CVE-2018-20372MedDec 23, 2018
    risk 0.35cvss 5.4epss 0.01

    TP-Link TD-W8961ND devices allow XSS via the hostname of a DHCP client.

  • CVE-2018-10165MedMay 3, 2018
    risk 0.35cvss 5.4epss 0.01

    Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the userName parameter in the local user creation functionality. This…

  • CVE-2018-10164MedMay 3, 2018
    risk 0.35cvss 5.4epss 0.01

    Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implementation of portalPictureUpload functionality. This is…