← Back

Tp Link

tp-link

524 CVEs • 925 products

Products (925)

Click to collapse
Toggle
R473 Firmware
r473_firmware
R478 Firmware
r478_firmware
R483 Firmware
r483_firmware
R488 Firmware
r488_firmware
Tapo
tapo
Tl Sc3130
tl-sc3130
Tl Sc3130g
tl-sc3130g
Tl Sc3171
tl-sc3171
Tl Sc3171g
tl-sc3171g
Lm Firmware
lm_firmware

CVEs (524)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tp Link
1Tl Wr886n Firmware
Nov 21, 2024
Sep 13, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for wlan_access name.
1Tp Link
1Tl Wr840n Firmware
Nov 21, 2024
Aug 15, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
1Tp Link
1Wr840n
Nov 21, 2024
Jul 19, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets with random MAC addresses.
1Tp Link
1Archer C1200 Firmware
Nov 21, 2024
Jul 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI.
1Tp Link
1Tl Wr841n Firmware
Nov 21, 2024
Jul 2, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow authenticated blind Command Injection.
1Tp Link
1Tl Wr841n Firmware
Nov 21, 2024
Jul 2, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking.
1Tp Link
1Tl Wr841n Firmware
Nov 21, 2024
Jul 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of authentication via an HTTP request.
1Tp Link
1Tl Wr841n Firmware
Nov 21, 2024
Jul 2, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF exists for all actions in the web interface on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices.
1Tp Link
1Tl Wa850re Firmware
Nov 21, 2024
Jun 23, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote attackers to cause a denial of service (reboot) via data/reboot.json.
1Tp Link
1Tl Wa850re Firmware
Nov 21, 2024
Jun 23, 2018
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to cause a denial of service (outage) via a long type parameter to /data/syslog.filter.json...Show more
Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to cause a denial of service (outage) via a long type parameter to /data/syslog.filter.json.Show less
1Tp Link
1Tl Wa850re Firmware
Nov 21, 2024
Jun 23, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the wps_setup_pin parameter to /data/wps.setup.json.
1Tp Link
2Tl Wr840n Firmware
Tl Wr841n Firmware
Nov 21, 2024
Jun 4, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session...Show more
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.Show less
1Tp Link
4Ipc Tl Ipc223(p) 6 Firmware
Tl Ipc323k D FirmwareTl Ipc325(kp) Firmware+1 more
Nov 21, 2024
May 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
/usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 password.
1Tp Link
4Ipc Tl Ipc223(p) 6 Firmware
Tl Ipc323k D FirmwareTl Ipc325(kp) Firmware+1 more
Nov 21, 2024
May 30, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices allow authenticated remote code execution via crafted JSON data because /usr/lib/lua/luci/torchlight/validator.lua does not block various...Show more
TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices allow authenticated remote code execution via crafted JSON data because /usr/lib/lua/luci/torchlight/validator.lua does not block various punctuation characters.Show less
1Tp Link
1Eap Controller
Nov 21, 2024
May 3, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of the Web API, allowing a low-privilege user to make any request as an Administrator. This is fixed in...Show more
TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of the Web API, allowing a low-privilege user to make any request as an Administrator. This is fixed in version 2.6.1_Windows.Show less
1Tp Link
1Eap Controller
Nov 21, 2024
May 3, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-coded cryptographic key, so anyone who knows that key and the algorithm can...Show more
The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-coded cryptographic key, so anyone who knows that key and the algorithm can decrypt it. A low-privilege user could decrypt and modify the backup file in order to elevate their privileges. This is fixed in version 2.6.1_Windows.Show less
1Tp Link
1Eap Controller
Nov 21, 2024
May 3, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens in any forms. This would allow an attacker to submit authenticated reque...Show more
The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens in any forms. This would allow an attacker to submit authenticated requests when an authenticated user browses an attack-controlled domain. This is fixed in version 2.6.1_Windows.Show less
1Tp Link
1Eap Controller
Nov 21, 2024
May 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the userNa...Show more
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the userName parameter in the local user creation functionality. This is fixed in version 2.6.1_Windows.Show less
1Tp Link
1Eap Controller
Nov 21, 2024
May 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implem...Show more
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implementation of portalPictureUpload functionality. This is fixed in version 2.6.1_Windows.Show less
1Tp Link
37Er5110g Firmware
Er5120g FirmwareEr5510g Firmware+34 more
Nov 21, 2024
Jan 11, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the pptphellointerval variable in the pptp_server.lua file.