Tp Link
tp-link
545 CVEs • 1,107 products
Products (1,107)
Click to collapseToggle
Products (1,107)
Click to collapse
CVEs (545)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Tp Link 18Dr3150 Firmware Dr3220v 4g FirmwareDr3650v 4g Firmware+15 moreSep 3, 2026 Aug 20, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection es...Show more |
1Tp Link 4Archer Mr600 Firmware Tl Mr100 FirmwareTl Mr150 Firmware+1 moreSep 3, 2026 Aug 20, 2026 7.1 HIGH· v4 7.5 HIGH· v3 N/A· v2 An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a...Show more |
1Tp Link 2Tapo C100 Firmware Tapo C101 FirmwareSep 4, 2026 Aug 19, 2026 6.9 MEDIUM· v4 5.7 MEDIUM· v3 N/A· v2 Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, res...Show more |
1Tp Link 2Tapo C100 Firmware Tapo C101 FirmwareSep 4, 2026 Aug 19, 2026 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resu...Show more |
An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5. An attacker can send oversized crypted ciphertext values that may tri...Show more |
1Tp Link 2Tapo C120 Firmware Tapo C200 FirmwareSep 4, 2026 Aug 18, 2026 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to...Show more |
Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead...Show more |
1Tp Link 109Omada Ds1008x Firmware Omada Ds1016g FirmwareOmada Ds1016ge Firmware+106 moreAug 7, 2026 Aug 3, 2026 5.7 MEDIUM· v4 5.9 MEDIUM· v3 N/A· v2 A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stor...Show more |
1Tp Link 112Omada Ds1008x Firmware Omada Ds1016g FirmwareOmada Ds1016ge Firmware+109 moreAug 7, 2026 Aug 3, 2026 5.8 MEDIUM· v4 5.9 MEDIUM· v3 N/A· v2 A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning in...Show more |
1Tp Link 112Omada Ds1008x Firmware Omada Ds1016g FirmwareOmada Ds1016ge Firmware+109 moreAug 7, 2026 Aug 3, 2026 6.9 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in sessio...Show more |
1Tp Link 112Omada Ds1008x Firmware Omada Ds1016g FirmwareOmada Ds1016ge Firmware+109 moreAug 7, 2026 Aug 3, 2026 8.2 HIGH· v4 7.5 HIGH· v3 N/A· v2 Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able t...Show more |
1Tp Link 112Omada Ds1008x Firmware Omada Ds1016g FirmwareOmada Ds1016ge Firmware+109 moreAug 7, 2026 Aug 3, 2026 6.9 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during...Show more |
1Tp Link 113Omada Omada Ds1008x FirmwareOmada Ds1016g Firmware+110 moreAug 7, 2026 Aug 3, 2026 6.9 MEDIUM· v4 5.9 MEDIUM· v3 N/A· v2 A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide suff...Show more |
1Tp Link 109Omada Ds1008x Firmware Omada Ds1016g FirmwareOmada Ds1016ge Firmware+106 moreAug 7, 2026 Aug 3, 2026 7.7 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to...Show more |
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a special...Show more |
1Tp Link 2Kasa Ec70 Firmware Kasa Ec71 FirmwareAug 6, 2026 Jul 15, 2026 8.6 HIGH· v4 5.3 MEDIUM· v3 N/A· v2 Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with access to the firmware image can extract the embedded key....Show more |
1Tp Link 2Kasa Ec70 Firmware Kasa Ec71 FirmwareAug 6, 2026 Jul 15, 2026 5.3 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue al...Show more |
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attac...Show more |
1Tp Link 1Archer Vx1800v Firmware Aug 6, 2026 Jul 14, 2026 5.1 MEDIUM· v4 8.8 HIGH· v3 N/A· v2 A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed co...Show more |
1Tp Link 1Archer Vx1800v Firmware Aug 6, 2026 Jul 14, 2026 8.5 HIGH· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the paramet...Show more |