VYPR

Vendor CVEs

TP-Link

All CVEs

614 total · sorted by risk
  • CVE-2026-0631HigFeb 2, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS Command Injection vulnerability exists in the Surfshark VPN login functionality in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1, allowing an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full…

  • CVE-2026-0630HigFeb 2, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device,…

  • CVE-2025-14737HigDec 18, 2025
    risk 0.52cvss 8.0epss 0.01

    Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922.

  • CVE-2025-32107HigApr 11, 2025
    risk 0.52cvss 8.0epss 0.02

    OS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123". If this vulnerability is exploited, an arbitrary OS command may be executed by the user who can log in to the device.

  • CVE-2024-57357HigFeb 7, 2025
    risk 0.52cvss 8.0epss 0.05

    An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to execute arbitrary code via function sub_4256CC, which allows command injection by injecting 'devpwd'.

  • CVE-2024-54887HigJan 9, 2025
    risk 0.52cvss 8.0epss 0.06

    TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the…

  • CVE-2024-46341HigDec 10, 2024
    risk 0.52cvss 8.0epss 0.00

    TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker executing a man-in-the-middle attack.

  • CVE-2024-50699HigDec 10, 2024
    risk 0.52cvss 8.0epss 0.00

    TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials for the Administrator account.

  • CVE-2024-11237HigNov 15, 2024
    risk 0.52cvss 7.5epss 0.05

    A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functionality of the component DHCP DISCOVER Packet Parser. The manipulation of the argument hostname leads to stack-based buffer…

  • CVE-2024-46486HigOct 4, 2024
    risk 0.52cvss 8.0epss 0.01

    TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.

  • CVE-2024-46313HigSep 30, 2024
    risk 0.52cvss 8.0epss 0.02

    TP-Link WR941ND V6 has a stack overflow vulnerability in the ssid parameter in /userRpm/popupSiteSurveyRpm.htm.

  • CVE-2023-41184HigMay 3, 2024
    risk 0.52cvss 8.0epss 0.01

    TP-Link Tapo C210 ActiveCells Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Tapo C210 IP cameras. Although authentication is required to exploit…

  • CVE-2024-1180HigApr 3, 2024
    risk 0.52cvss 8.0epss 0.01

    TP-Link Omada ER605 Access Control Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605. Authentication is required to exploit this vulnerability. …

  • CVE-2024-21821HigJan 11, 2024
    risk 0.52cvss 8.0epss 0.00

    Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands.

  • CVE-2023-40531HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Archer AX6000 firmware versions prior to 'Archer AX6000(JP)_V1_1.3.0 Build 20221208' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.

  • CVE-2023-40357HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer…

  • CVE-2023-40193HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Deco M4 firmware versions prior to 'Deco M4(JP)_V2_1.5.8 Build 20230619' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.

  • CVE-2023-39935HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Archer C5400 firmware versions prior to 'Archer C5400(JP)_V2_230506' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.

  • CVE-2023-39224HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Note that Archer C5 is no longer supported, therefore the update for this product is not provided.

  • CVE-2023-38588HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Archer C3150 firmware versions prior to 'Archer C3150(JP)_V2_230511' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.

  • CVE-2023-31188HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505', Archer C55 firmware versions prior to 'Archer…

  • CVE-2022-37255HigApr 16, 2023
    risk 0.52cvss 7.5epss 0.05

    TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603.

  • CVE-2022-42433HigMar 29, 2023
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N TL-WR841N(US)_V14_220121 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be…

  • CVE-2022-24973HigMar 28, 2023
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the httpd…

  • CVE-2022-0650HigMar 28, 2023
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the httpd…

  • CVE-2021-37774HigJan 19, 2023
    risk 0.52cvss 8.0epss 0.01

    An issue was discovered in function httpProcDataSrv in TL-WDR7660 2.0.30 that allows attackers to execute arbitrary code.

  • CVE-2020-10916HigMay 7, 2020
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA855RE Firmware Ver: 855rev4-up-ver1-0-1-P1[20191213-rel60361] Wi-Fi extenders. Although authentication is required to exploit this vulnerability, the existing…

  • CVE-2018-15172HigAug 15, 2018
    risk 0.52cvss 7.5epss 0.08

    TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.

  • CVE-2018-14336HigJul 19, 2018
    risk 0.52cvss 7.5epss 0.08

    TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets with random MAC addresses.

  • CVE-2026-0651HigFeb 10, 2026
    risk 0.51cvss 7.8epss 0.00

    A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and falls back to using the raw path when…

  • CVE-2022-26988HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.02

    TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution.

  • CVE-2022-26987HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.02

    TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.

  • CVE-2018-3948HigNov 30, 2018
    risk 0.51cvss 7.5epss 0.23

    An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP server. A specially crafted URL can cause the server to stop responding to requests, resulting in downtime for the management portal. An attacker can send either…

  • CVE-2026-17176HigSep 11, 2026
    risk 0.50cvss —epss 0.04

    An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete device compromise, including…

  • CVE-2026-18167HigSep 3, 2026
    risk 0.50cvss —epss 0.00

    A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve remote code execution on the device. …

  • CVE-2026-15469HigAug 24, 2026
    risk 0.50cvss —epss 0.00

    The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6.  A shared RSA-512 mesh group private key is present in the affected firmware and is used by the mesh protocol for node…

  • CVE-2023-36358HigJun 22, 2023
    risk 0.50cvss 7.7epss 0.01

    TP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR841N V8 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlAccessTargetsRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

  • CVE-2023-36357HigJun 22, 2023
    risk 0.50cvss 7.7epss 0.01

    An issue in the /userRpm/LocalManageControlRpm component of TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8/V10, and TL-WR941ND V5 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

  • CVE-2023-36356HigJun 22, 2023
    risk 0.50cvss 7.7epss 0.01

    TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8, TL-WR941ND V5, and TL-WR740N V1/V2 were discovered to contain a buffer read out-of-bounds via the component /userRpm/VirtualServerRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

  • CVE-2020-12695HigJun 8, 2020
    risk 0.50cvss 7.5epss 0.15

    The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

  • CVE-2018-16119HigJun 20, 2019
    risk 0.50cvss 7.2epss 0.34

    Stack-based buffer overflow in the httpd server of TP-Link WR1043nd (Firmware Version 3) allows remote attackers to execute arbitrary code via a malicious MediaServer request to /userRpm/MediaServerFoldersCfgRpm.htm.

  • CVE-2025-56565HigSep 16, 2026
    risk 0.49cvss 7.6epss 0.00

    DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH private keys, dynamic DNS passwords, email notification credentials and administrative…

  • CVE-2026-8619HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference.  A remote attacker on an…

  • CVE-2026-15314HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.01

    Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service…

  • CVE-2025-15629HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully…

  • CVE-2025-15628HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept…

  • CVE-2025-15627HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.01

    A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to…

  • CVE-2026-34126HigMay 28, 2026
    risk 0.49cvss 7.5epss 0.00

    TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext without encryption. Bluetooth is only used during initialization. An attacker…

  • CVE-2026-3622HigMar 26, 2026
    risk 0.49cvss 7.5epss 0.01

    The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-bounds read, potentially causing a crash of the UPnP service. Successful exploitation can cause the UPnP service to crash, resulting in a Denial-of-Service…

  • CVE-2025-15606HigMar 23, 2026
    risk 0.49cvss 7.5epss 0.00

    A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitization, allows crafted requests to trigger a processing error that causes the httpd service to crash. Successful exploitation may allow the attacker to cause…

Page 6 of 13