Tp Link
tp-link
524 CVEs • 925 products
Products (925)
Click to collapseToggle
Products (925)
Click to collapse
CVEs (524)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Tp Link 2Tapo C220 Firmware Tapo C520ws FirmwareJun 17, 2026 Jan 27, 2026 7.1 HIGH· v4 7.5 HIGH· v3 N/A· v2 By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying authentication or firmware integrity. An unauthenticated attacker can tr...Show more |
1Tp Link 2Tapo C220 Firmware Tapo C520ws FirmwareJun 17, 2026 Jan 27, 2026 7.1 HIGH· v4 7.5 HIGH· v3 N/A· v2 The HTTP parser of Tapo C210 v3, C220 v1 and C520WS v2 cameras improperly handles requests containing an excessively long URL path. An invalid‑URL error path continues into cleanup code that assumes allocated buffers exi...Show more |
1Tp Link 2Tapo C220 Firmware Tapo C520ws FirmwareJun 17, 2026 Jan 27, 2026 7.1 HIGH· v4 7.5 HIGH· v3 N/A· v2 The Tapo C100 v5, C220 v1 and C520WS v2 cameras’ HTTP service does not safely handle POST requests containing an excessively large Content-Length header. The resulting failed memory allocation triggers a NULL pointer der...Show more |
Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information. |
Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to we...Show more |
An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account. |
Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted inpu...Show more |
1Tp Link 56Beam Bridge 5 Ur Firmware Dr3220v 4g FirmwareDr3650v 4g Firmware+53 moreJun 17, 2026 Jan 23, 2026 6.0 MEDIUM· v4 5.9 MEDIUM· v3 N/A· v2 An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and all...Show more |
1Tp Link 5Oc200 Firmware Oc220 FirmwareOc300 Firmware+2 moreJun 17, 2026 Jan 22, 2026 5.7 MEDIUM· v4 4.7 MEDIUM· v3 N/A· v2 A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trus...Show more |
1Tp Link 2Archer Ax53 Firmware Archer C20 FirmwareJun 17, 2026 Jan 21, 2026 7.2 HIGH· v4 8.8 HIGH· v3 N/A· v2 Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot w...Show more |
A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input validation. A remote, unauthenticated attacker can exploit this flaw and c...Show more |
1Tp Link 1Archer Axe75 Firmware Jun 17, 2026 Jan 9, 2026 6.9 MEDIUM· v4 7.3 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary server file, leading to possible loss of critical system files and service...Show more |
1Tp Link 1Archer Be400 Firmware Jun 17, 2026 Jan 7, 2026 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows an adjacent attacker to cause a denial-of-service (DoS) by triggering a device reboot. This issue affects Archer BE400: xi 1.1...Show more |
1Tp Link 1Tl Wr820n Firmware Jun 17, 2026 Dec 29, 2025 6.0 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and decrypt SSH traffic. Exploitation may expose sensitive informa...Show more |
A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length be...Show more |
The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, re...Show more |
The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests...Show more |
Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This issue affects: ≤ WA850RE V2_160527,
≤
WA850RE V3_160922. |
Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue affects: ≤ WA850RE V2_160527,
≤
WA850RE V3_160922. |
1Tp Link 13Er605 Firmware Er706w 4g FirmwareEr706w Firmware+10 moreJun 17, 2026 Oct 21, 2025 8.7 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. |