VYPR

Vendor CVEs

TP-Link

All CVEs

614 total · sorted by risk
  • CVE-2024-21773HigJan 11, 2024
    risk 0.57cvss 8.8epss 0.01

    Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control settings.

  • CVE-2023-43138HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.02

    TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT rules after authentication, and the rule name has an injection point.

  • CVE-2023-43137HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.02

    TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rules after authentication, and the rule name parameter has injection points.

  • CVE-2023-38568HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.00

    Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504' allows a network-adjacent unauthenticated attacker to execute arbitrary OS commands.

  • CVE-2023-38563HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.01

    Archer C1200 firmware versions prior to 'Archer C1200(JP)_V2_230508' and Archer C9 firmware versions prior to 'Archer C9(JP)_V3_230508' allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands.

  • CVE-2023-37284HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper authentication vulnerability in Archer C20 firmware versions prior to 'Archer C20(JP)_V1_230616' allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command via a crafted request to bypass authentication.

  • CVE-2023-36489HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.01

    Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: TL-WR802N firmware versions prior to 'TL-WR802N(JP)_V4_221008', TL-WR841N firmware versions prior to…

  • CVE-2023-32619HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.00

    Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506' use hard-coded credentials to login to the affected device, which may allow a network-adjacent unauthenticated attacker to execute an arbitrary…

  • CVE-2023-28478HigJun 12, 2023
    risk 0.57cvss 8.8epss 0.00

    TP-Link EC-70 devices through 2.3.4 Build 20220902 rel.69498 have a Buffer Overflow.

  • CVE-2023-31701HigMay 17, 2023
    risk 0.57cvss 8.8epss 0.02

    TP-Link TL-WPA4530 KIT V2 (EU)_170406 and V2 (EU)_161115 is vulnerable to Command Injection via _httpRpmPlcDeviceRemove.

  • CVE-2023-31700HigMay 17, 2023
    risk 0.57cvss 8.8epss 0.02

    TP-Link TL-WPA4530 KIT V2 (EU)_170406 and V2 (EU)_161115 is vulnerable to Command Injection via _httpRpmPlcDeviceAdd.

  • CVE-2022-43636HigMar 29, 2023
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which…

  • CVE-2022-24353HigMar 28, 2023
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 1.1.4 Build 20211022 rel.59103(5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB.ko…

  • CVE-2022-24352HigMar 28, 2023
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 prior to 211210 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB.ko kernel module. The…

  • CVE-2022-46914HigDec 20, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue in the firmware update process of TP-LINK TL-WA801N / TL-WA801ND V1 v3.12.16 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.

  • CVE-2022-46912HigDec 20, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue in the firmware update process of TP-Link TL-WR841N / TL-WA841ND V7 3.13.9 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.

  • CVE-2022-46910HigDec 20, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue in the firmware update process of TP-Link TL-WA901ND V1 up to v3.11.2 and TL-WA901N V2 up to v3.12.16 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.

  • CVE-2022-46435HigDec 20, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue in the firmware update process of TP-Link TL-WR941ND V2/V3 up to 3.13.9 and TL-WR941ND V4 up to 3.12.8 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.

  • CVE-2022-40486HigSep 28, 2022
    risk 0.57cvss 8.8epss 0.02

    TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated attackers to execute arbitrary code via a crafted backup file.

  • CVE-2022-30024HigJul 14, 2022
    risk 0.57cvss 8.8epss 0.02

    A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network. This affects TL-WR841 V12…

  • CVE-2022-24355HigFeb 18, 2022
    risk 0.57cvss 8.8epss 0.02

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing…

  • CVE-2022-24354HigFeb 18, 2022
    risk 0.57cvss 8.8epss 0.02

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 prior to 1.1.4 Build 20211022 rel.59103(5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2021-4144HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.02

    TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.

  • CVE-2021-31659HigJun 10, 2021
    risk 0.57cvss 8.8epss 0.01

    TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information is placed in the URL, without any additional token authentication information. A malicious link opened by the switch administrator…

  • CVE-2020-24297HigNov 18, 2020
    risk 0.57cvss 8.8epss 0.04

    httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS commands by sending crafted POST requests to the endpoint /admin/powerline. Fixed version: TL-WPA4220(EU)_V4_201023

  • CVE-2020-15055HigAug 7, 2020
    risk 0.57cvss 8.8epss 0.01

    TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.

  • CVE-2020-15054HigAug 7, 2020
    risk 0.57cvss 8.8epss 0.00

    TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.

  • CVE-2020-13224HigJun 17, 2020
    risk 0.57cvss 8.8epss 0.02

    TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through 1.3.1 build 200401, NC260 devices through 1.5.3 build_200401, and NC450 devices…

  • CVE-2013-4848HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.01

    TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.

  • CVE-2019-13268HigAug 27, 2019
    risk 0.57cvss 8.8epss 0.01

    TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To…

  • CVE-2019-13267HigAug 27, 2019
    risk 0.57cvss 8.8epss 0.01

    TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. In order to transfer data from the host network to the guest network, the sender joins and then leaves an…

  • CVE-2019-13266HigAug 27, 2019
    risk 0.57cvss 8.8epss 0.01

    TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the…

  • CVE-2018-3950HigDec 1, 2018
    risk 0.57cvss 8.8epss 0.03

    An exploitable remote code execution vulnerability exists in the ping and tracert functionality of the TP-Link TL-R600VPN HWv3 FRNv1.3.0 and HWv2 FRNv1.2.3 http server. A specially crafted IP address can cause a stack overflow, resulting in remote code execution. An attacker can…

  • CVE-2018-15702HigOct 1, 2018
    risk 0.57cvss 8.8epss 0.00

    The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to CSRF due to insufficient validation of the referer field.

  • CVE-2018-12577HigJul 2, 2018
    risk 0.57cvss 8.8epss 0.03

    The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow authenticated blind Command Injection.

  • CVE-2018-12574HigJul 2, 2018
    risk 0.57cvss 8.8epss 0.00

    CSRF exists for all actions in the web interface on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices.

  • CVE-2018-11481HigMay 30, 2018
    risk 0.57cvss 8.8epss 0.02

    TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices allow authenticated remote code execution via crafted JSON data because /usr/lib/lua/luci/torchlight/validator.lua does not block various punctuation characters.

  • CVE-2018-10168HigMay 3, 2018
    risk 0.57cvss 8.8epss 0.01

    TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of the Web API, allowing a low-privilege user to make any request as an Administrator. This is fixed in version 2.6.1_Windows.

  • CVE-2018-10166HigMay 3, 2018
    risk 0.57cvss 8.8epss 0.01

    The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens in any forms. This would allow an attacker to submit authenticated requests when an authenticated user browses an attack-controlled…

  • CVE-2017-17758HigDec 19, 2017
    risk 0.57cvss 8.8epss 0.03

    TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/dhcps command to cgi-bin/luci, related to the zone_get_iface_bydev function in /usr/lib/lua/luci/controller/admin/dhcps.lua…

  • CVE-2017-17757HigDec 19, 2017
    risk 0.57cvss 8.8epss 0.03

    TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/wportal.lua…

  • CVE-2017-16960HigNov 27, 2017
    risk 0.57cvss 8.8epss 0.02

    TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in…

  • CVE-2017-16958HigNov 27, 2017
    risk 0.57cvss 8.8epss 0.03

    TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in…

  • CVE-2025-30241HigAug 10, 2026
    risk 0.56cvss —epss 0.00

    Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions.  An authenticated adjacent attacker may inject specially crafted input to execute…

  • CVE-2025-30238HigAug 10, 2026
    risk 0.56cvss —epss 0.00

    In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged operations. An attacker may perform administrative actions such as creating privileged accounts or modifying critical…

  • CVE-2023-50224MedKEVMay 3, 2024
    risk 0.56cvss 6.5epss 0.16

    TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit…

  • CVE-2026-85384HigSep 8, 2026
    risk 0.55cvss —epss 0.00

    A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration…

  • CVE-2026-78541HigAug 24, 2026
    risk 0.55cvss —epss 0.02

    A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during…

  • CVE-2026-16348HigAug 24, 2026
    risk 0.55cvss —epss 0.02

    An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.  Successful exploitation may enable…

  • CVE-2026-17250HigAug 21, 2026
    risk 0.55cvss —epss 0.00

    A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlled metadata within a firmware image. Successful exploitation may allow an authenticated attacker to trigger memory…

Page 4 of 13