← Back

Tp Link

tp-link

524 CVEs • 925 products

Products (925)

Click to collapse
Toggle
R473 Firmware
r473_firmware
R478 Firmware
r478_firmware
R483 Firmware
r483_firmware
R488 Firmware
r488_firmware
Tapo
tapo
Tl Sc3130
tl-sc3130
Tl Sc3130g
tl-sc3130g
Tl Sc3171
tl-sc3171
Tl Sc3171g
tl-sc3171g
Lm Firmware
lm_firmware

CVEs (524)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tp Link
1Tl Wr940n V4 Firmware
Jun 17, 2026
Dec 20, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
TP-Link TL-WR940N V4 3.16.9 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.
1Tp Link
1Re3000 Firmware
Jun 17, 2026
Dec 7, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
tdpServer of TP-Link RE300 V1 improperly processes its input, which may allow an attacker to cause a denial-of-service (DoS) condition of the product's OneMesh function.
1Tp Link
1Tl Wr740n Firmware
Jun 17, 2026
Dec 6, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A vulnerability classified as problematic has been found in TP-Link TL-WR740N. Affected is an unknown function of the component ARP Handler. The manipulation leads to resource consumption. The attack needs to be done wit...Show more
A vulnerability classified as problematic has been found in TP-Link TL-WR740N. Affected is an unknown function of the component ARP Handler. The manipulation leads to resource consumption. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214812.Show less
1Tp Link
1Ax10 Firmware
Jun 17, 2026
Oct 18, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
TP-Link AX10v1 V1_211117 allows attackers to execute a replay attack by using a previously transmitted encrypted authentication message and valid authentication token. Attackers are able to login to the web application a...Show more
TP-Link AX10v1 V1_211117 allows attackers to execute a replay attack by using a previously transmitted encrypted authentication message and valid authentication token. Attackers are able to login to the web application as an admin user.Show less
1Tp Link
1Ax10 Firmware
Jun 17, 2026
Oct 18, 2022
N/A· v4
5.9 MEDIUM· v3
N/A· v2
The web app client of TP-Link AX10v1 V1_211117 uses hard-coded cryptographic keys when communicating with the router. Attackers who are able to intercept the communications between the web client and router through a man...Show more
The web app client of TP-Link AX10v1 V1_211117 uses hard-coded cryptographic keys when communicating with the router. Attackers who are able to intercept the communications between the web client and router through a man-in-the-middle attack can then obtain the sequence key via a brute-force attack, and access sensitive information.Show less
1Tp Link
1Tl Wr841n Firmware
Jun 17, 2026
Oct 18, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
TP-Link TL-WR841N 8.0 4.17.16 Build 120201 Rel.54750n is vulnerable to Cross Site Scripting (XSS).
1Tp Link
1Archer Ax10 V1 Firmware
Jun 17, 2026
Sep 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated attackers to execute arbitrary code via a crafted backup file.
1Tp Link
1M7350 Firmware
Jun 17, 2026
Sep 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerability.
1Tp Link
1Archer A7 Firmware
Jul 9, 2026
Aug 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This...Show more
TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on the router.Show less
1Tp Link
1Tl R473g Firmware
Jun 17, 2026
Jul 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is exploited via a crafted packet.
1Tp Link
3Tl Wr841 Firmware
Tl Wr841n(eu) FirmwareTl Wr841n Firmware
Jul 9, 2026
Jul 14, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the...Show more
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network. This affects TL-WR841 V12 TL-WR841N(EU)_V12_160624 and TL-WR841 V11 TL-WR841N(EU)_V11_160325 , TL-WR841N_V11_150616 and TL-WR841 V10 TL-WR841N_V10_150310 are also affected.Show less
1Tp Link
2Tl Wr741n Firmware
Tl Wr742n Firmware
Jun 17, 2026
Jul 7, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An infinite loop in the function httpRpmPass of TP-Link TL-WR741N/TL-WR742N V1/V2/V3_130415 allows attackers to cause a Denial of Service (DoS) via a crafted packet.
1Tp Link
2Archer A5 Firmware
Archer C50 Firmware
Jun 17, 2026
Jun 30, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A stack overflow in the function DM_ In fillobjbystr() of TP-Link Archer C50&A5(US)_V5_200407 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
1Tp Link
1Archer Ax50 Firmware
Jul 9, 2026
Jun 9, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.
1Tp Link
1Tl Wr840n Firmware
Jun 17, 2026
May 25, 2022
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allows attackers to connect to the UART port via a serial connection and execute commands as the root use...Show more
TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allows attackers to connect to the UART port via a serial connection and execute commands as the root user without authentication.Show less
3Fastcom
MercusysTp Link
6Fac1900r Firmware
Mercury D196g FirmwareTl Wdr5660 Firmware+3 more
Jul 9, 2026
May 10, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution.
3Fastcom
MercusysTp Link
6Fac1900r Firmware
Mercury D196g FirmwareTl Wdr5660 Firmware+3 more
Jul 9, 2026
May 10, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.
1Tp Link
1Tl Wr840n Firmware
Jun 17, 2026
Apr 18, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Tp-Link TL-WR840N (EU) v6.20 Firmware (0.9.1 4.17 v0001.0 Build 201124 Rel.64328n) is vulnerable to Buffer Overflow via the Password reset feature.
1Tp Link
1Tl Wr840n Firmware
Jun 17, 2026
Mar 28, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter.
1Tp Link
1Tl Wr840n Firmware
Jun 17, 2026
Mar 28, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.