← Back

Tp Link

tp-link

524 CVEs • 925 products

Products (925)

Click to collapse
Toggle
R473 Firmware
r473_firmware
R478 Firmware
r478_firmware
R483 Firmware
r483_firmware
R488 Firmware
r488_firmware
Tapo
tapo
Tl Sc3130
tl-sc3130
Tl Sc3130g
tl-sc3130g
Tl Sc3171
tl-sc3171
Tl Sc3171g
tl-sc3171g
Lm Firmware
lm_firmware

CVEs (524)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tp Link
2Tapo C220 Firmware
Tapo C520ws Firmware
Jun 17, 2026
Jan 27, 2026
7.1 HIGH· v4
7.5 HIGH· v3
N/A· v2
By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying authentication or firmware integrity. An unauthenticated attacker can tr...Show more
By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying authentication or firmware integrity. An unauthenticated attacker can trigger a persistent denial of service, requiring a manual reboot or application initiated restart to restore normal device operation.Show less
1Tp Link
2Tapo C220 Firmware
Tapo C520ws Firmware
Jun 17, 2026
Jan 27, 2026
7.1 HIGH· v4
7.5 HIGH· v3
N/A· v2
The HTTP parser of Tapo C210 v3, C220 v1 and C520WS v2 cameras improperly handles requests containing an excessively long URL path. An invalid‑URL error path continues into cleanup code that assumes allocated buffers exi...Show more
The HTTP parser of Tapo C210 v3, C220 v1 and C520WS v2 cameras improperly handles requests containing an excessively long URL path. An invalid‑URL error path continues into cleanup code that assumes allocated buffers exist, leading to a crash and service restart. An unauthenticated attacker can force repeated service crashes or device reboots, causing denial of service.Show less
1Tp Link
2Tapo C220 Firmware
Tapo C520ws Firmware
Jun 17, 2026
Jan 27, 2026
7.1 HIGH· v4
7.5 HIGH· v3
N/A· v2
The Tapo C100 v5, C220 v1 and C520WS v2 cameras’ HTTP service does not safely handle POST requests containing an excessively large Content-Length header. The resulting failed memory allocation triggers a NULL pointer der...Show more
The Tapo C100 v5, C220 v1 and C520WS v2 cameras’ HTTP service does not safely handle POST requests containing an excessively large Content-Length header. The resulting failed memory allocation triggers a NULL pointer dereference, causing the main service process to crash. An unauthenticated attacker can repeatedly crash the service, causing temporary denial of service. The device restarts automatically, and repeated requests can keep it unavailable.Show less
1Tp Link
1Omada Controller
Jun 17, 2026
Jan 26, 2026
5.1 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information.
1Tp Link
1Omada Controller
Jun 17, 2026
Jan 26, 2026
2.1 LOW· v4
6.5 MEDIUM· v3
N/A· v2
Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to we...Show more
Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to weakened account security.Show less
1Tp Link
1Omada Controller
Jun 17, 2026
Jan 26, 2026
8.3 HIGH· v4
6.8 MEDIUM· v3
N/A· v2
An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account.
1Tp Link
1Archer Mr600 Firmware
Jun 17, 2026
Jan 26, 2026
8.5 HIGH· v4
8.8 HIGH· v3
N/A· v2
Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted inpu...Show more
Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to service disruption or full compromise.Show less
1Tp Link
56Beam Bridge 5 Ur Firmware
Dr3220v 4g FirmwareDr3650v 4g Firmware+53 more
Jun 17, 2026
Jan 23, 2026
6.0 MEDIUM· v4
5.9 MEDIUM· v3
N/A· v2
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and all...Show more
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.Show less
1Tp Link
5Oc200 Firmware
Oc220 FirmwareOc300 Firmware+2 more
Jun 17, 2026
Jan 22, 2026
5.7 MEDIUM· v4
4.7 MEDIUM· v3
N/A· v2
A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trus...Show more
A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker could execute arbitrary JavaScript in the administrator’s browser, potentially exposing sensitive information and compromising confidentiality.Show less
1Tp Link
2Archer Ax53 Firmware
Archer C20 Firmware
Jun 17, 2026
Jan 21, 2026
7.2 HIGH· v4
8.8 HIGH· v3
N/A· v2
Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot w...Show more
Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials. Attackers on the adjacent network can remotely trigger factory resets and reboots without credentials, causing configuration loss and interruption of device availability. This issue affects Archer C20 v6.0 < V6_251031, Archer C20 v5 <EU_V5_260317 or < US_V5_260419 Archer AX53 v1.0 < V1_251215 TL-WR841N v13 < 0.9.1 Build 20231120 Rel.62366Show less
1Tp Link
1Tl Wr841n Firmware
Jun 17, 2026
Jan 15, 2026
6.3 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input validation.  A remote, unauthenticated attacker can exploit this flaw and c...Show more
A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input validation.  A remote, unauthenticated attacker can exploit this flaw and cause Denial of Service on the web portal service.This issue affects TL-WR841N v14: before 250908.Show less
1Tp Link
1Archer Axe75 Firmware
Jun 17, 2026
Jan 9, 2026
6.9 MEDIUM· v4
7.3 HIGH· v3
N/A· v2
Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary server file, leading to possible loss of critical system files and service...Show more
Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary server file, leading to possible loss of critical system files and service interruption or degraded functionality.This issue affects Archer AXE75 v1.6: ≤ build 20250107.Show less
1Tp Link
1Archer Be400 Firmware
Jun 17, 2026
Jan 7, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows  an adjacent attacker to cause a denial-of-service (DoS) by triggering a device reboot. This issue affects Archer BE400: xi 1.1...Show more
A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows  an adjacent attacker to cause a denial-of-service (DoS) by triggering a device reboot. This issue affects Archer BE400: xi 1.1.0 Build 20250710 rel.14914.Show less
1Tp Link
1Tl Wr820n Firmware
Jun 17, 2026
Dec 29, 2025
6.0 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and decrypt SSH traffic. Exploitation may expose sensitive informa...Show more
A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and decrypt SSH traffic. Exploitation may expose sensitive information and compromise confidentiality.Show less
1Tp Link
1Tapo C200 Firmware
Jun 17, 2026
Dec 20, 2025
8.7 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length be...Show more
A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer. It allowed a crafted SOAP request with an oversized namespace prefix to cause memory corruption in stack. An unauthenticated attacker on the same local network may exploit this flaw to enable remote code execution with elevated privileges, leading to full compromise of the device.Show less
1Tp Link
1Tapo C200 Firmware
Jun 17, 2026
Dec 20, 2025
8.7 HIGH· v4
8.1 HIGH· v3
N/A· v2
The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, re...Show more
The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).Show less
1Tp Link
1Tapo C200 Firmware
Jun 17, 2026
Dec 20, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests...Show more
The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests to trigger excessive memory allocation, causing the device to crash and resulting in denial-of-service (DoS).Show less
1Tp Link
1Tl Wa850re Firmware
Jun 17, 2026
Dec 18, 2025
5.7 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922.
1Tp Link
1Tl Wa850re Firmware
Jun 17, 2026
Dec 18, 2025
7.1 HIGH· v4
8.0 HIGH· v3
N/A· v2
Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922.
1Tp Link
13Er605 Firmware
Er706w 4g FirmwareEr706w Firmware+10 more
Jun 17, 2026
Oct 21, 2025
8.7 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.