← Back

Tp Link

tp-link

545 CVEs • 1,107 products

Products (1,107)

Click to collapse
Toggle
R473 Firmware
r473_firmware
R478 Firmware
r478_firmware
R483 Firmware
r483_firmware
R488 Firmware
r488_firmware
Tapo
tapo

CVEs (545)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tp Link
18Dr3150 Firmware
Dr3220v 4g FirmwareDr3650v 4g Firmware+15 more
Sep 3, 2026
Aug 20, 2026
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection es...Show more
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.  Successful exploitation may allow arbitrary command execution, potentially leading to full compromise of the affected device.Show less
1Tp Link
4Archer Mr600 Firmware
Tl Mr100 FirmwareTl Mr150 Firmware+1 more
Sep 3, 2026
Aug 20, 2026
7.1 HIGH· v4
7.5 HIGH· v3
N/A· v2
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a...Show more
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference.  A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.Show less
1Tp Link
2Tapo C100 Firmware
Tapo C101 Firmware
Sep 4, 2026
Aug 19, 2026
6.9 MEDIUM· v4
5.7 MEDIUM· v3
N/A· v2
Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, res...Show more
Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bounds heap writes. Successful exploitation can crash the RTSP service and trigger a device reboot, resulting in a temporary denial-of-service condition.Show less
1Tp Link
2Tapo C100 Firmware
Tapo C101 Firmware
Sep 4, 2026
Aug 19, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resu...Show more
Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful exploitation can disrupt live video streaming functionality and cause a temporary denial-of-service condition.Show less
1Tp Link
1Tapo C200 Firmware
Sep 4, 2026
Aug 18, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted ciphertext values that may tri...Show more
An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart. Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers.Show less
1Tp Link
2Tapo C120 Firmware
Tapo C200 Firmware
Sep 4, 2026
Aug 18, 2026
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to...Show more
Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.Show less
1Tp Link
1Tapo P110 Firmware
Aug 7, 2026
Aug 4, 2026
7.1 HIGH· v4
7.5 HIGH· v3
N/A· v2
Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead...Show more
Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash. Successful exploitation may cause the web service process to stop responding or restart, resulting in a denial-of-service condition.Show less
1Tp Link
109Omada Ds1008x Firmware
Omada Ds1016g FirmwareOmada Ds1016ge Firmware+106 more
Aug 7, 2026
Aug 3, 2026
5.7 MEDIUM· v4
5.9 MEDIUM· v3
N/A· v2
A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stor...Show more
A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments.Show less
1Tp Link
112Omada Ds1008x Firmware
Omada Ds1016g FirmwareOmada Ds1016ge Firmware+109 more
Aug 7, 2026
Aug 3, 2026
5.8 MEDIUM· v4
5.9 MEDIUM· v3
N/A· v2
A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning in...Show more
A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. Successful exploitation may allow disclosure of provisioning information intended for a legitimate device.Show less
1Tp Link
112Omada Ds1008x Firmware
Omada Ds1016g FirmwareOmada Ds1016ge Firmware+109 more
Aug 7, 2026
Aug 3, 2026
6.9 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in sessio...Show more
A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be able to recover session encryption keys and decrypt affected communications.Show less
1Tp Link
112Omada Ds1008x Firmware
Omada Ds1016g FirmwareOmada Ds1016ge Firmware+109 more
Aug 7, 2026
Aug 3, 2026
8.2 HIGH· v4
7.5 HIGH· v3
N/A· v2
Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able t...Show more
Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications.Show less
1Tp Link
112Omada Ds1008x Firmware
Omada Ds1016g FirmwareOmada Ds1016ge Firmware+109 more
Aug 7, 2026
Aug 3, 2026
6.9 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during...Show more
A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications.Show less
1Tp Link
113Omada
Omada Ds1008x FirmwareOmada Ds1016g Firmware+110 more
Aug 7, 2026
Aug 3, 2026
6.9 MEDIUM· v4
5.9 MEDIUM· v3
N/A· v2
A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide suff...Show more
A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments.Show less
1Tp Link
109Omada Ds1008x Firmware
Omada Ds1016g FirmwareOmada Ds1016ge Firmware+106 more
Aug 7, 2026
Aug 3, 2026
7.7 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to...Show more
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.Show less
1Tp Link
1Archer Axe75 Firmware
Aug 7, 2026
Jul 31, 2026
8.5 HIGH· v4
8.0 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a special...Show more
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters.  Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability.Show less
1Tp Link
2Kasa Ec70 Firmware
Kasa Ec71 Firmware
Aug 6, 2026
Jul 15, 2026
8.6 HIGH· v4
5.3 MEDIUM· v3
N/A· v2
Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.  An attacker with access to the firmware image can extract the embedded key....Show more
Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.  An attacker with access to the firmware image can extract the embedded key.  Successful exploitation may allow an unauthenticated attacker on the same network to use this key in the web management service, compromising the confidentiality of encrypted communications. This may enable passive decryption of traffic or active man-in-the-middle (MITM) attacksShow less
1Tp Link
2Kasa Ec70 Firmware
Kasa Ec71 Firmware
Aug 6, 2026
Jul 15, 2026
5.3 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue al...Show more
An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted responses. The vulnerability impacts confidentiality only, with no evidence of integrity of availability impact.Show less
1Tp Link
1Deco M5 Firmware
Aug 6, 2026
Jul 14, 2026
7.1 HIGH· v4
6.7 MEDIUM· v3
N/A· v2
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attac...Show more
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of authentication credentials, enabling unauthorized access to device management functions, depending on the privileges associated with the recovered password. The primary security impact is loss of confidentiality.Show less
1Tp Link
1Archer Vx1800v Firmware
Aug 6, 2026
Jul 14, 2026
5.1 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed co...Show more
A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data.  An authenticated user with sufficient privileges may be able to modify account settings and gain elevated administrative privileges.Show less
1Tp Link
1Archer Vx1800v Firmware
Aug 6, 2026
Jul 14, 2026
8.5 HIGH· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the paramet...Show more
An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges. Successful exploitation may allow remote code execution and complete compromise of the device.Show less