VYPR

Vendor CVEs

TP-Link

All CVEs

614 total · sorted by risk
  • CVE-2017-8218CriApr 25, 2017
    risk 0.64cvss 9.8epss 0.02

    vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n has a backdoor admin account with the 1234 password, a backdoor guest account with the guest password, and a backdoor test account with the test password.

  • CVE-2017-8076CriApr 23, 2017
    risk 0.64cvss 9.8epss 0.01

    On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is deprecated. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.

  • CVE-2017-8075CriApr 23, 2017
    risk 0.64cvss 9.8epss 0.02

    On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.

  • CVE-2017-8074CriApr 23, 2017
    risk 0.64cvss 9.8epss 0.02

    On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadecimal. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.

  • CVE-2022-48194HigDec 30, 2022
    risk 0.63cvss 8.8epss 0.33

    TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.

  • CVE-2022-30075HigJun 9, 2022
    risk 0.63cvss 8.8epss 0.34

    In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.

  • CVE-2021-44827HigMar 4, 2022
    risk 0.62cvss 8.8epss 0.54

    There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_ExternalIPv6Address HTTP parameter, allowing a remote attacker to run arbitrary commands on the router with root privileges.

  • CVE-2020-10884HigMar 25, 2020
    risk 0.62cvss 8.8epss 0.22

    This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service,…

  • CVE-2019-6989HigJun 6, 2019
    risk 0.61cvss 8.8epss 0.11

    TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispose function. By sending specially crafted ICMP echo request packets, a remote authenticated attacker could overflow a buffer and execute arbitrary code on the…

  • CVE-2025-9377HigKEVAug 29, 2025
    risk 0.60cvss 7.2epss 0.34

    The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the…

  • CVE-2025-40634CriMay 20, 2025
    risk 0.60cvss —epss 0.01

    Stack-based buffer overflow vulnerability in the 'conn-indicator' binary running as root on the TP-Link Archer AX50 router, in firmware versions prior to 1.0.15 build 241203 rel61480. This vulnerability allows an attacker to execute arbitrary code on the device over LAN and WAN…

  • CVE-2018-12692HigJun 23, 2018
    risk 0.60cvss 8.8epss 0.29

    TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the wps_setup_pin parameter to /data/wps.setup.json.

  • CVE-2026-0652HigFeb 10, 2026
    risk 0.59cvss 8.8epss 0.22

    On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and…

  • CVE-2026-1457HigJan 29, 2026
    risk 0.58cvss 8.8epss 0.08

    An authenticated buffer handling flaw in TP-Link VIGI C385 V1 Web API lacking input sanitization, may allow memory corruption leading to remote code execution. Authenticated attackers may trigger buffer overflow and potentially execute arbitrary code with elevated privileges.

  • CVE-2020-12111HigMay 4, 2020
    risk 0.58cvss 8.8epss 0.08

    Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.

  • CVE-2019-17147HigJan 7, 2020
    risk 0.58cvss 8.8epss 0.14

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 80 by default.…

  • CVE-2019-15060HigAug 22, 2019
    risk 0.58cvss 8.8epss 0.04

    The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payload in an IP address input field.

  • CVE-2019-12104HigAug 14, 2019
    risk 0.58cvss 8.8epss 0.05

    The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-authentication command injection vulnerabilities.

  • CVE-2019-6487HigJan 18, 2019
    risk 0.58cvss 8.8epss 0.09

    TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather get_weather_observe citycode field.

  • CVE-2017-16957HigNov 27, 2017
    risk 0.58cvss 8.8epss 0.06

    TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zone_get_effect_devices function in…

  • CVE-2026-75118HigAug 28, 2026
    risk 0.57cvss —epss 0.00

    A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds checking of encrypted requests to the /cgi/login endpoint. An adjacent unauthenticated attacker with access to the router's web…

  • CVE-2026-76784HigAug 26, 2026
    risk 0.57cvss —epss 0.00

    Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device…

  • CVE-2026-9254HigAug 24, 2026
    risk 0.57cvss —epss 0.03

    An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary…

  • CVE-2025-30237HigAug 10, 2026
    risk 0.57cvss —epss 0.00

    The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted requests to bypass authentication and directly invoke privileged…

  • CVE-2026-15429HigJul 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data.  An authenticated user with…

  • CVE-2026-15428HigJul 14, 2026
    risk 0.57cvss 8.8epss 0.02

    An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary…

  • CVE-2026-11834HigJun 22, 2026
    risk 0.57cvss —epss 0.01

    A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient validation of externally supplied DHCP option data. An adjacent attacker may exploit this vulnerability by supplying crafted DHCP…

  • CVE-2026-8697HigMay 28, 2026
    risk 0.57cvss 8.8epss 0.00

    Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web interface. This enables an attacker to brute-force valid credentials via SSH. …

  • CVE-2026-3294HigMay 22, 2026
    risk 0.57cvss 8.8epss 0.01

    An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to…

  • CVE-2026-5039HigApr 23, 2026
    risk 0.57cvss 8.8epss 0.00

    TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default web management credentials, making the key predictable if device is left in default configuration. A network-adjacent attacker can exploit this weakness to…

  • CVE-2026-5363HigApr 16, 2026
    risk 0.57cvss 8.8epss 0.00

    Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login.  An adjacent attacker…

  • CVE-2026-34121HigApr 2, 2026
    risk 0.57cvss 8.8epss 0.00

    An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to inconsistent parsing and authorization logic in JSON requests during authentication check. An unauthenticated attacker can append…

  • CVE-2026-3841HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.03

    A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient sanitization of data processed during specific CLI operations. An authenticated attacker with elevated privileges…

  • CVE-2025-15557HigFeb 5, 2026
    risk 0.57cvss 8.8epss 0.00

    An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications.  This may compromise the confidentiality and integrity of…

  • CVE-2025-13399HigJan 29, 2026
    risk 0.57cvss 8.8epss 0.00

    A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force the weak AES key and decrypt intercepted traffic. Successful exploitation requires network proximity but no authentication, and may result in high impact to…

  • CVE-2025-14756HigJan 26, 2026
    risk 0.57cvss 8.8epss 0.03

    Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to…

  • CVE-2026-0834HigJan 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials. Attackers on the adjacent network can…

  • CVE-2025-6541HigOct 21, 2025
    risk 0.57cvss 8.8epss 0.01

    An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.

  • CVE-2025-9961HigSep 6, 2025
    risk 0.57cvss —epss 0.10

    An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.  The exploit can only be conducted via a Man-In-The-Middle (MITM) attack.  This issue affects AX10 V1/V1.2/V2/V2.6/V3/V3.6: before 1.2.1; AX1500…

  • CVE-2025-8627HigAug 25, 2025
    risk 0.57cvss 8.8epss 0.00

    The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off condition and potential information leak. This issue affects TP-Link KP303 (US) Smartplug: before 1.1.0.

  • CVE-2025-7724HigJul 22, 2025
    risk 0.57cvss —epss 0.01

    An unauthenticated OS command injection vulnerability exists in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1: before 1.1.5 Build 250518; VIGI NVR2016H-16MP V2: before 1.3.1 Build 250407.

  • CVE-2025-5875HigJun 9, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in TP-LINK Technologies TL-IPC544EP-W4 1.0.9 Build 240428 Rel 69493n. Affected is the function sub_69064 of the file /bin/main. The manipulation of the argument text leads to buffer overflow. It is possible to launch the…

  • CVE-2024-5035HigMay 27, 2024
    risk 0.57cvss —epss 0.03

    The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ports TCP/8888, TCP/8889, and TCP/8890. By successfully exploiting this flaw, remote unauthenticated attacker can gain arbitrary command execution on the…

  • CVE-2023-39471HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. …

  • CVE-2023-35717HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    TP-Link Tapo C210 Password Recovery Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link Tapo C210 IP cameras. Authentication is not required to exploit this vulnerability. The…

  • CVE-2023-27346HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    TP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AX1800 routers. Authentication is not required to exploit this…

  • CVE-2023-27332HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    TP-Link Archer AX21 tdpServer Logging Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer AX21 routers. Authentication is not required to…

  • CVE-2024-1179HigApr 1, 2024
    risk 0.57cvss 8.8epss 0.01

    TP-Link Omada ER605 DHCPv6 Client Options Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to…

  • CVE-2023-43318HigMar 6, 2024
    risk 0.57cvss 8.8epss 0.01

    TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.

  • CVE-2024-21833HigJan 11, 2024
    risk 0.57cvss 8.8epss 0.01

    Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.

Page 3 of 13