Tp Link
tp-link
524 CVEs • 925 products
Products (925)
Click to collapseToggle
Products (925)
Click to collapse
CVEs (524)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Tp Link 37Er5110g Firmware Er5120g FirmwareEr5510g Firmware+34 moreNov 21, 2024 Jan 11, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-interface variable in the phddns.lua file. |
1Tp Link 37Er5110g Firmware Er5120g FirmwareEr5510g Firmware+34 moreNov 21, 2024 Jan 11, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the lcpechointerval variable in the pptp_client.lua file. |
1Tp Link 37Er5110g Firmware Er5120g FirmwareEr5510g Firmware+34 moreNov 21, 2024 Jan 11, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-outif variable in the pptp_client.lua file. |
1Tp Link 37Er5110g Firmware Er5120g FirmwareEr5510g Firmware+34 moreNov 21, 2024 Jan 11, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-interface variable in the cmxddns.lua file. |
Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service condition. |
Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials. The authentication record is stored o...Show more |
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName' parameter. |
1Tp Link 15Tl War1200l Firmware Tl War1300l FirmwareTl War1750l Firmware+12 moreMay 13, 2026 Dec 19, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/dhcps command to cgi-bin/luci, related to the zone_get_iface_by...Show more |
1Tp Link 15Tl War1200l Firmware Tl War1300l FirmwareTl War1750l Firmware+12 moreMay 13, 2026 Dec 19, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif...Show more |
1Tp Link 54Tl Er3210g Firmware Tl Er3220g FirmwareTl Er5110g Firmware+51 moreMay 13, 2026 Nov 27, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the...Show more |
1Tp Link 51Tl Er3210g Firmware Tl Er3220g FirmwareTl Er5110g Firmware+48 moreMay 13, 2026 Nov 27, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and th...Show more |
1Tp Link 51Tl Er3210g Firmware Tl Er3220g FirmwareTl Er5110g Firmware+48 moreMay 13, 2026 Nov 27, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get...Show more |
1Tp Link 51Tl Er3210g Firmware Tl Er3220g FirmwareTl Er5110g Firmware+48 moreMay 13, 2026 Nov 27, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zo...Show more |
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserve...Show more |
1Tp Link 1Tl Mr3220 Firmware May 13, 2026 Oct 20, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject arbitrary web script or HTML via the Description field. |
1Tp Link 1Archer C9 (2.0) Firmware May 13, 2026 Jul 21, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random number generator seed. This is fixed in C9(UN)_V2_170511. |
On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:554/h264_hd.sdp URL. |
The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption. This resulted in incorrect access control, which allowed attackers to ga...Show more |
1Tp Link 2C20i Firmware C2 FirmwareMay 13, 2026 Apr 25, 2017 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by placing shell commands in a "host=" line within HTTP POST data. |
1Tp Link 2C20i Firmware C2 FirmwareMay 13, 2026 Apr 25, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow DoSing the HTTP server via a crafted Cookie header to the /cgi/ansi URI. |