← Back

Tp Link

tp-link

524 CVEs • 925 products

Products (925)

Click to collapse
Toggle
R473 Firmware
r473_firmware
R478 Firmware
r478_firmware
R483 Firmware
r483_firmware
R488 Firmware
r488_firmware
Tapo
tapo
Tl Sc3130
tl-sc3130
Tl Sc3130g
tl-sc3130g
Tl Sc3171
tl-sc3171
Tl Sc3171g
tl-sc3171g
Lm Firmware
lm_firmware

CVEs (524)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tp Link
1Ac1750 Firmware
Jun 17, 2026
Mar 25, 2020
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerabil...Show more
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service, which listens on UDP port 20002 by default. When parsing the slave_mac parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-9650.Show less
1Tp Link
1Ac1750 Firmware
Jun 17, 2026
Mar 25, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The s...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A crafted DNS message can trigger an overflow of a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-9660.Show less
1Tp Link
1Archer C50
Jun 17, 2026
Mar 25, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.
1Tp Link
1Tl Wr849n Firmware
Jun 17, 2026
Feb 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature.
1Tp Link
1Tp Sg105e Firmware
Jun 17, 2026
Feb 3, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the device via a reboot.cgi request.
1Tp Link
1Tl Wr1043nd Firmware
Nov 21, 2024
Feb 3, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TP-LINK TL-WR1043ND V1_120405 devices contain an unspecified denial of service vulnerability.
1Tp Link
3Tl Sc 3130g Firmware
Tl Sc 3171g FirmwareTl Sc 4171g Firmware
Nov 21, 2024
Jan 29, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G. and 4171G 1.6.18P12s, which could let a malicious user execute...Show more
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G. and 4171G 1.6.18P12s, which could let a malicious user execute arbitrary code.Show less
1Tp Link
4Tl Sc 3130 Firmware
Tl Sc 3130g FirmwareTl Sc 3171g Firmware+1 more
Nov 21, 2024
Jan 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicio...Show more
A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicious user obtain unauthorized access to CGI files.Show less
1Tp Link
1Tl Wr849n Firmware
Jun 17, 2026
Jan 27, 2020
N/A· v4
6.1 MEDIUM· v3
4.1 MEDIUM· v2
TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI.
1Tp Link
1Tl Wr841n Firmware
Jun 17, 2026
Jan 7, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within t...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 80 by default. When parsing the Host request header, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length static buffer. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-8457.Show less
1Tp Link
2Tl 1043nd Firmware
Tl Wdr4300 Firmware
Nov 21, 2024
Nov 13, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND..
1Tp Link
1Tl Wdr4300 Firmware
Nov 21, 2024
Oct 25, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.
1Tp Link
1M7350 Firmware
Jun 17, 2026
Oct 24, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow triggerPort OS Command Injection (issue 5 of 5).
1Tp Link
1M7350 Firmware
Jun 17, 2026
Oct 24, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow serviceName OS Command Injection (issue 4 of 5).
1Tp Link
1M7350 Firmware
Jun 17, 2026
Oct 24, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow portMappingProtocol OS Command Injection (issue 3 of 5).
1Tp Link
1M7350 Firmware
Jun 17, 2026
Oct 24, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow internalPort OS Command Injection (issue 2 of 5).
1Tp Link
1M7350 Firmware
Jun 17, 2026
Oct 24, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow externalPort OS Command Injection (issue 1 of 5).
1Tp Link
2Archer C2 V1 Firmware
Archer C3200 V1 Firmware
Jun 17, 2026
Aug 27, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as bro...Show more
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert channel, the sender can trivially issue an ARP request to an arbitrary computer on the network. (In general, some routers restrict ARP forwarding only to requests destined for the network's subnet mask, but these routers did not restrict this traffic in any way. Depending on this factor, one must use either the lower 8 bits of the IP address, or the entire 32 bits, as the data payload.)Show less
1Tp Link
2Archer C2 V1 Firmware
Archer C3200 V1 Firmware
Jun 17, 2026
Aug 27, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. In order to transfer data from the host network...Show more
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. In order to transfer data from the host network to the guest network, the sender joins and then leaves an IGMP group. After it leaves, the router (following the IGMP protocol) creates an IGMP Membership Query packet with the Group IP and sends it to both the Host and the Guest networks. The data is transferred within the Group IP field, which is completely controlled by the sender.Show less
1Tp Link
2Archer C2 V1 Firmware
Archer C3200 V1 Firmware
Jun 17, 2026
Aug 27, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a cert...Show more
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with an ACK or NAK message. Studying the NAK case revealed that the router erroneously sends the NAK to both Host and Guest networks with the same Transaction ID as found in the DHCP Request. This allows encoding of data to be sent cross-router into the 32-bit Transaction ID field.Show less