← Back

Tl Wdr4300 Firmware

tl-wdr4300_firmware

Vendor: Tp Link • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tp Link
36Archer C1900 Firmware
Archer C5 FirmwareArcher C7 Firmware+33 more
Sep 3, 2026
May 3, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-W...Show more
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.Show less
1Tp Link
2Tl 1043nd Firmware
Tl Wdr4300 Firmware
Nov 21, 2024
Nov 13, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND..
1Tp Link
1Tl Wdr4300 Firmware
Nov 21, 2024
Oct 25, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.
1Tp Link
5Tl Wdr3500 Firmware
Tl Wdr3600 FirmwareTl Wdr4300 Firmware+2 more
Jun 17, 2026
Jan 18, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather get_w...Show more
TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather get_weather_observe citycode field.Show less
1Tp Link
25Archer C5 (1.2) Firmware
Archer C5 FirmwareArcher C7 (2.0) Firmware+22 more
Apr 21, 2026
Apr 22, 2015
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0...Show more
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.Show less
1Tp Link
2Tl Wdr4300
Tl Wdr4300 Firmware
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The web server in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to cause a denial of service (crash) via a long header in a GET request.
1Tp Link
2Tl Wdr4300
Tl Wdr4300 Firmware
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the DHCP clients page in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to inject arbitrary web script or H...Show more
Cross-site scripting (XSS) vulnerability in the DHCP clients page in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to inject arbitrary web script or HTML via the hostname in a DHCP request.Show less