VYPR

Vendor CVEs

TP-Link

All CVEs

614 total · sorted by risk
  • CVE-2018-15840HigMar 29, 2019
    risk 0.49cvss 7.5epss 0.02

    TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets, as demonstrated by an "nmap -f" command.

  • CVE-2018-12694HigJun 23, 2018
    risk 0.49cvss 7.5epss 0.01

    TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote attackers to cause a denial of service (reboot) via data/reboot.json.

  • CVE-2018-10167HigMay 3, 2018
    risk 0.49cvss 7.5epss 0.01

    The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-coded cryptographic key, so anyone who knows that key and the algorithm can decrypt it. A low-privilege user could decrypt and modify…

  • CVE-2017-8077HigApr 23, 2017
    risk 0.49cvss 7.5epss 0.01

    On the TP-Link TL-SG108E 1.0, there is a hard-coded ciphering key (a long string beginning with Ei2HNryt). This affects the 1.1.2 Build 20141017 Rel.50749 firmware.

  • CVE-2016-1000009HigOct 6, 2016
    risk 0.49cvss 7.5epss 0.01

    TP-LINK lost control of two domains, www.tplinklogin.net and tplinkextender.net. Please note that these domains are physically printed on many of the devices.

  • CVE-2026-80712HigAug 28, 2026
    risk 0.48cvss 8.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: write the feature value before executing SET_FEATURE qcom_spi_send_cmdaddr() programs NAND_FLASH_CMD/NAND_EXEC_CMD and submits the descriptors, which makes the controller execute the…

  • CVE-2026-19683HigAug 20, 2026
    risk 0.48cvss 7.4epss 0.00

    A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an…

  • CVE-2020-8423HigApr 2, 2020
    risk 0.48cvss 7.2epss 0.09

    A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the configuration of the Wi-Fi network.

  • CVE-2026-11410HigJun 17, 2026
    risk 0.47cvss 7.2epss 0.03

    An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with…

  • CVE-2026-11409HigJun 17, 2026
    risk 0.47cvss 7.2epss 0.03

    An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated…

  • CVE-2026-5509HigMay 27, 2026
    risk 0.47cvss 7.2epss 0.05

    An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary system commands through the web management interface. After successfully authenticating to the admin interface, an attacker can…

  • CVE-2025-15605HigMar 23, 2026
    risk 0.47cvss 7.3epss 0.00

    A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data. An authenticated attacker may decrypt configuration files, modify them, and re-encrypt them,…

  • CVE-2025-15519HigMar 23, 2026
    risk 0.47cvss 7.2epss 0.01

    Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary…

  • CVE-2025-15518HigMar 23, 2026
    risk 0.47cvss 7.2epss 0.01

    Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary…

  • CVE-2026-22229HigFeb 2, 2026
    risk 0.47cvss 7.2epss 0.02

    A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN client configuration file on the TP-Link Archer BE230 v1.2 and Deco BE25 v1.0. Successful exploitation could allow an attacker to gain full administrative control…

  • CVE-2026-22227HigFeb 2, 2026
    risk 0.47cvss 7.2epss 0.03

    A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restoration function of the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in…

  • CVE-2026-22226HigFeb 2, 2026
    risk 0.47cvss 7.2epss 0.03

    A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration module on TP-Link Archer BE230 v1.2 and Archer AX73 v2. Successful exploitation could allow an attacker to gain full administrative control of the device,…

  • CVE-2026-22225HigFeb 2, 2026
    risk 0.47cvss 7.2epss 0.03

    A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the Archer BE230 v1.2  and Archer AXE75 v1.0. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in…

  • CVE-2026-22224HigFeb 2, 2026
    risk 0.47cvss 7.2epss 0.03

    A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface on the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe…

  • CVE-2025-15035HigJan 9, 2026
    risk 0.47cvss 7.3epss 0.00

    Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary server file, leading to possible loss of critical system files and service interruption or degraded functionality.This issue affects…

  • CVE-2025-7850HigOct 21, 2025
    risk 0.47cvss 7.2epss 0.03

    A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.

  • CVE-2024-21827HigJun 25, 2024
    risk 0.47cvss 7.2epss 0.01

    A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of…

  • CVE-2023-49913HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.02

    A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An…

  • CVE-2023-49912HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.02

    A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An…

  • CVE-2023-49911HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.02

    A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An…

  • CVE-2023-49910HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.02

    A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An…

  • CVE-2023-49909HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.02

    A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An…

  • CVE-2023-49908HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.02

    A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An…

  • CVE-2023-49907HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.02

    A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An…

  • CVE-2023-49906HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.02

    A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An…

  • CVE-2023-47618HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.02

    A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an…

  • CVE-2023-47617HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an…

  • CVE-2023-47209HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an…

  • CVE-2023-47167HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated…

  • CVE-2023-46683HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection . An attacker can…

  • CVE-2023-43482HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to…

  • CVE-2023-42664HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an…

  • CVE-2023-36498HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an…

  • CVE-2021-46122HigApr 18, 2022
    risk 0.47cvss 7.2epss 0.02

    Tp-Link TL-WR840N (EU) v6.20 Firmware (0.9.1 4.17 v0001.0 Build 201124 Rel.64328n) is vulnerable to Buffer Overflow via the Password reset feature.

  • CVE-2022-26642HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.01

    TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter.

  • CVE-2022-26641HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.01

    TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.

  • CVE-2022-26640HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.01

    TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter.

  • CVE-2022-26639HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.01

    TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter.

  • CVE-2018-3951HigDec 1, 2018
    risk 0.47cvss 7.2epss 0.04

    An exploitable remote code execution vulnerability exists in the HTTP header-parsing function of the TP-Link TL-R600VPN HTTP Server. A specially crafted HTTP request can cause a buffer overflow, resulting in remote code execution on the device. An attacker can send an…

  • CVE-2018-19537HigNov 26, 2018
    risk 0.47cvss 7.2epss 0.06

    TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuration file that is encrypted with the 478DA50BF9E3D2CF key and uploaded through the web GUI by using the web admin account. The…

  • CVE-2017-15637HigJan 11, 2018
    risk 0.47cvss 7.2epss 0.04

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the pptphellointerval variable in the pptp_server.lua file.

  • CVE-2017-15636HigJan 11, 2018
    risk 0.47cvss 7.2epss 0.04

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-time variable in the webfilter.lua file.

  • CVE-2017-15635HigJan 11, 2018
    risk 0.47cvss 7.2epss 0.04

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the max_conn variable in the session_limits.lua file.

  • CVE-2017-15634HigJan 11, 2018
    risk 0.47cvss 7.2epss 0.04

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the name variable in the wportal.lua file.

  • CVE-2017-15633HigJan 11, 2018
    risk 0.47cvss 7.2epss 0.04

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-ipgroup variable in the session_limits.lua file.

Page 8 of 13