← Back

Tp Link

tp-link

524 CVEs • 925 products

Products (925)

Click to collapse
Toggle
R473 Firmware
r473_firmware
R478 Firmware
r478_firmware
R483 Firmware
r483_firmware
R488 Firmware
r488_firmware
Tapo
tapo
Tl Sc3130
tl-sc3130
Tl Sc3130g
tl-sc3130g
Tl Sc3171
tl-sc3171
Tl Sc3171g
tl-sc3171g
Lm Firmware
lm_firmware

CVEs (524)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tp Link
1Er7206 Firmware
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitra...Show more
A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Tp Link
1Er7206 Firmware
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request c...Show more
A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection . An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Tp Link
1Er7206 Firmware
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execu...Show more
A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Tp Link
1Er7206 Firmware
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can l...Show more
A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Tp Link
1Er7206 Firmware
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitr...Show more
A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability and gain access to an unrestricted shell.Show less
1Tp Link
2Tapo C200 Firmware
Tapo Tc70 Firmware
Jun 17, 2026
Jan 17, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proximate attacker to obtain sensitive information via a connection to the UART pin c...Show more
Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proximate attacker to obtain sensitive information via a connection to the UART pin components.Show less
1Tp Link
5Archer Ax3000 Firmware
Archer Ax5400 FirmwareArcher Axe75 Firmware+2 more
Jun 17, 2026
Jan 11, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN...Show more
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.Show less
1Tp Link
3Archer Ax3000 Firmware
Archer Ax5400 FirmwareArcher Axe75 Firmware
Jun 17, 2026
Jan 11, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands.
1Tp Link
4Archer Ax3000 Firmware
Archer Ax5400 FirmwareDeco X50 Firmware+1 more
Jun 17, 2026
Jan 11, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and...Show more
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control settings.Show less
1Tp Link
1Tapo
Jul 9, 2026
Jan 9, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
1Tp Link
1Tapo
Jun 17, 2026
Dec 28, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.
1Tp Link
1Tapo C100 Firmware
Jun 17, 2026
Oct 31, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted web request.
1Tp Link
1Tl Wr886n Firmware
Jun 17, 2026
Oct 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function registerRequestHandle.
1Tp Link
1Tl Wr886n Firmware
Jun 17, 2026
Oct 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkResetVeriRegister.
1Tp Link
1Tl Wr886n Firmware
Jun 17, 2026
Oct 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getRegVeriRegister.
1Tp Link
1Tl Wr886n Firmware
Jun 17, 2026
Oct 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkRegVeriRegister.
1Tp Link
1Tl Wr886n Firmware
Jun 17, 2026
Oct 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getResetVeriRegister.
1Tp Link
1Tl Wr886n Firmware
Jun 17, 2026
Oct 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function modifyAccPwdRegister.
1Tp Link
1Tl Wr886n Firmware
Jun 17, 2026
Oct 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 was discovered to contain a stack overflow via the function bindRequestHandle.
1Tp Link
1Tl Wr886n Firmware
Jun 17, 2026
Oct 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function resetCloudPwdRegister.