Tp Link
tp-link
524 CVEs • 925 products
Products (925)
Click to collapseToggle
Products (925)
Click to collapse
CVEs (524)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Tp Link 2C20i Firmware C2 FirmwareMay 13, 2026 Apr 25, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n has a backdoor admin account with the 1234 password, a backdoor guest account with the guest password, and a backdoor test...Show more |
1Tp Link 2C20i Firmware C2 FirmwareMay 13, 2026 Apr 25, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n have too permissive iptables rules, e.g., SNMP is not blocked on any interface. |
On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd). This affects the 1.1.2 Build 20141017 Rel.50749 firmware. |
On the TP-Link TL-SG108E 1.0, there is a hard-coded ciphering key (a long string beginning with Ei2HNryt). This affects the 1.1.2 Build 20141017 Rel.50749 firmware. |
On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is deprecated. This affects the 1.1.2 Build 20141017 Rel.50749 firmware. |
1Tp Link 1Tl Sg108e Firmware May 13, 2026 Apr 23, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext. This affects the 1.1.2 Build 20141017 Rel.50749 firmware. |
1Tp Link 1Tl Sg108e Firmware May 13, 2026 Apr 23, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadecimal. This affects the 1.1.2 Build 20141017 Rel.50749 firmware. |
TP-LINK lost control of two domains, www.tplinklogin.net and tplinkextender.net. Please note that these domains are physically printed on many of the devices. |
1Tp Link 25Archer C5 (1.2) Firmware Archer C5 FirmwareArcher C7 (2.0) Firmware+22 moreApr 21, 2026 Apr 22, 2015 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0...Show more |
Cross-site request forgery (CSRF) vulnerability in the administration console in TP-Link TL-WR840N (V1) router with firmware before 3.13.27 build 141120 allows remote attackers to hijack the authentication of administrat...Show more |
TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a denial of service (httpd crash) via vectors involving a "new" value in the isNew para...Show more |
Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_120405 allow remote attackers to hijack the authentication of administrators for requests that (1) ena...Show more |
1Tp Link 2Tl Wdr4300 Tl Wdr4300 FirmwareMay 6, 2026 Sep 30, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The web server in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to cause a denial of service (crash) via a long header in a GET request. |
1Tp Link 2Tl Wdr4300 Tl Wdr4300 FirmwareMay 6, 2026 Sep 30, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the DHCP clients page in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to inject arbitrary web script or H...Show more |
1Tp Link 2Tl Wr841n Tl Wr841n FirmwareMay 6, 2026 Sep 30, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in the TP-LINK TL-WR841N router with firmware 3.13.9 Build 120201 Rel.54965n and earlier allow remote administrators to inject arbitrary web script or HTML via the (1)...Show more |
6Allegrosoft DlinkHuawei+3 more7Dsl 2640r Dsl 2641rMt882+4 moreApr 29, 2026 Jan 16, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author head...Show more |
1Tp Link 5Lm Firmware Tl Sc3130Tl Sc3130g+2 moreApr 29, 2026 Oct 11, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to modify the firmware revision via a...Show more |
1Tp Link 5Lm Firmware Tl Sc3130Tl Sc3130g+2 moreApr 29, 2026 Oct 11, 2013 N/A· v4 N/A· v3 7.1 HIGH· v2 Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, allows remote attackers...Show more |
1Tp Link 5Lm Firmware Tl Sc3130Tl Sc3130g+2 moreApr 29, 2026 Oct 11, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an empty password for the hardcoded "qmik" account, which allows remote attackers to...Show more |
1Tp Link 5Lm Firmware Tl Sc3130Tl Sc3130g+2 moreApr 29, 2026 Oct 11, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shel...Show more |