← Back

Tp Link

tp-link

524 CVEs • 925 products

Products (925)

Click to collapse
Toggle
R473 Firmware
r473_firmware
R478 Firmware
r478_firmware
R483 Firmware
r483_firmware
R488 Firmware
r488_firmware
Tapo
tapo
Tl Sc3130
tl-sc3130
Tl Sc3130g
tl-sc3130g
Tl Sc3171
tl-sc3171
Tl Sc3171g
tl-sc3171g
Lm Firmware
lm_firmware

CVEs (524)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tp Link
37Er5110g Firmware
Er5120g FirmwareEr5510g Firmware+34 more
Nov 21, 2024
Jan 11, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-interface variable in the phddns.lua file.
1Tp Link
37Er5110g Firmware
Er5120g FirmwareEr5510g Firmware+34 more
Nov 21, 2024
Jan 11, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the lcpechointerval variable in the pptp_client.lua file.
1Tp Link
37Er5110g Firmware
Er5120g FirmwareEr5510g Firmware+34 more
Nov 21, 2024
Jan 11, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-outif variable in the pptp_client.lua file.
1Tp Link
37Er5110g Firmware
Er5120g FirmwareEr5510g Firmware+34 more
Nov 21, 2024
Jan 11, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-interface variable in the cmxddns.lua file.
1Tp Link
1Tl Sg108e Firmware
May 13, 2026
Dec 20, 2017
N/A· v4
6.5 MEDIUM· v3
2.7 LOW· v2
Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service condition.
1Tp Link
1Tl Sg108e Firmware
May 13, 2026
Dec 20, 2017
N/A· v4
6.8 MEDIUM· v3
7.7 HIGH· v2
Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials. The authentication record is stored o...Show more
Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials. The authentication record is stored on the device; thus if an administrator authenticates from a NAT network, the authentication applies to the IP address of the NAT gateway, and any user behind that NAT gateway is also treated as authenticated.Show less
1Tp Link
1Tl Sg108e Firmware
May 13, 2026
Dec 20, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName' parameter.
1Tp Link
15Tl War1200l Firmware
Tl War1300l FirmwareTl War1750l Firmware+12 more
May 13, 2026
Dec 19, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/dhcps command to cgi-bin/luci, related to the zone_get_iface_by...Show more
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/dhcps command to cgi-bin/luci, related to the zone_get_iface_bydev function in /usr/lib/lua/luci/controller/admin/dhcps.lua in uhttpd.Show less
1Tp Link
15Tl War1200l Firmware
Tl War1300l FirmwareTl War1750l Firmware+12 more
May 13, 2026
Dec 19, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif...Show more
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/wportal.lua in uhttpd.Show less
1Tp Link
54Tl Er3210g Firmware
Tl Er3220g FirmwareTl Er5110g Firmware+51 more
May 13, 2026
Nov 27, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the...Show more
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/interface.lua in uhttpd.Show less
1Tp Link
51Tl Er3210g Firmware
Tl Er3220g FirmwareTl Er5110g Firmware+48 more
May 13, 2026
Nov 27, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and th...Show more
The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the set_sysinfo and get_sysinfo functions in /usr/lib/lua/luci/controller/locale.lua in uhttpd.Show less
1Tp Link
51Tl Er3210g Firmware
Tl Er3220g FirmwareTl Er5110g Firmware+48 more
May 13, 2026
Nov 27, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get...Show more
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/bridge.lua in uhttpd.Show less
1Tp Link
51Tl Er3210g Firmware
Tl Er3220g FirmwareTl Er5110g Firmware+48 more
May 13, 2026
Nov 27, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zo...Show more
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zone_get_effect_devices function in /usr/lib/lua/luci/controller/admin/diagnostic.lua in uhttpd.Show less
1Tp Link
1Wr940n Firmware
May 13, 2026
Oct 23, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserve...Show more
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to WanStaticIpV6CfgRpm.htm.Show less
1Tp Link
1Tl Mr3220 Firmware
May 13, 2026
Oct 20, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject arbitrary web script or HTML via the Description field.
1Tp Link
1Archer C9 (2.0) Firmware
May 13, 2026
Jul 21, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random number generator seed. This is fixed in C9(UN)_V2_170511.
1Tp Link
1Nc250 Firmware
May 13, 2026
Jul 2, 2017
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:554/h264_hd.sdp URL.
1Tp Link
1Wr841n V8 Firmware
May 13, 2026
Jun 26, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption. This resulted in incorrect access control, which allowed attackers to ga...Show more
The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption. This resulted in incorrect access control, which allowed attackers to gain read-write access to system settings through the protected router configuration service tddp via the LAN and Ath0 (Wi-Fi) interfaces.Show less
1Tp Link
2C20i Firmware
C2 Firmware
May 13, 2026
Apr 25, 2017
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by placing shell commands in a "host=" line within HTTP POST data.
1Tp Link
2C20i Firmware
C2 Firmware
May 13, 2026
Apr 25, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow DoSing the HTTP server via a crafted Cookie header to the /cgi/ansi URI.