TP-Link kayıtları
tp-link üreticisine ait 554 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 6 · %1,1
- Silahlaştırılmış
- 13 · %2,3
- Pre-auth RCE
- 84
- Düzeltme kaydı olan
- %2,3
- Yayından KEV’e ortanca
- 615 gün
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')95
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')42
- CWE-787 Out-of-bounds Write36
- CWE-121 Stack-based Buffer Overflow34
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')22
- CWE-20 Improper Input Validation22
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
554 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
95Hemen | CVE-2023-1389Silahlaştırılmış | TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form otp-link · archer ax21 firmware · CWE-77 | Yüksek8,8 | KEV | %100,0 | 15 Mar 2023 |
85Hemen | CVE-2015-3035Silahlaştırılmış | Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0)tp-link · tl-wr741nd firmware · CWE-22 | Yüksek7,5 | KEV | %83,9 | 21 Nis 2015 |
77Bu hafta | CVE-2023-33538Silahlaştırılmış | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the componenttp-link · tl-wr940n firmware · CWE-77 | Yüksek8,8 | KEV | %41,6 | 7 Haz 2023 |
74Bu hafta | CVE-2025-9377Silahlaştırılmış | Authenticated RCE via Parental Control command injectiontp-link · tl-wr841n firmware · CWE-78 | Yüksek8,6 | KEV | %33,5 | 29 Ağu 2025 |
71Bu hafta | CVE-2020-24363Silahlaştırılmış | TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request tp-link · tl-wa855re firmware · CWE-306 | Yüksek8,8 | KEV | %20,7 | 31 Ağu 2020 |
63Bu hafta | CVE-2022-37860İstismar yok | The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vtp-link · m7350 firmware · CWE-78 | Kritik9,8 | — | %80,4 | 12 Eyl 2022 |
62Bu hafta | CVE-2021-41653Kavram kanıtı | The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code executiontp-link · tl-wr840n firmware · CWE-94 | Kritik9,8 | — | %76,0 | 13 Kas 2021 |
62Bu hafta | CVE-2020-28347Silahlaştırılmış | tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter.tp-link · ac1750 firmware · CWE-78 | Kritik9,8 | — | %75,4 | 8 Kas 2020 |
62Bu hafta | CVE-2013-2578Silahlaştırılmış | cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware Ltp-link · tl-sc3130 · CWE-78 | Kritik10,0 | — | %73,7 | 11 Eki 2013 |
61Bu hafta | CVE-2021-4045Kavram kanıtı | TP-LINK Tapo C200 remote code execution vulnerabilitytp-link · tapo c200 firmware · CWE-77 | Kritik9,8 | — | %72,4 | 10 Mar 2022 |
61Bu hafta | CVE-2023-50224Silahlaştırılmış | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerabilitytp-link · tl-wr841n firmware · CWE-290 | Orta6,5 | KEV | %15,6 | 2 May 2024 |
59Planlayın | CVE-2018-11714Kavram kanıtı | An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0tp-link · tl-wr840n firmware · CWE-384 | Kritik9,8 | — | %68,1 | 4 Haz 2018 |
57Planlayın | CVE-2020-12109Silahlaştırılmış | Certain TP-Link devices allow Command Injection.tp-link · nc200 firmware · CWE-78 | Yüksek8,8 | — | %74,3 | 4 May 2020 |
57Planlayın | CVE-2022-25061Kavram kanıtı | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.tp-link · tl-wr840n firmware · CWE-78 | Kritik9,8 | — | %58,7 | 25 Şub 2022 |
52Planlayın | CVE-2012-5687Silahlaştırılmış | Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.tp-link · tl-wr841n · CWE-22 | Yüksek7,8 | — | %68,7 | 1 Kas 2012 |
52Planlayın | CVE-2020-9374Kavram kanıtı | On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker tp-link · tl-wr849n firmware · CWE-78 | Kritik9,8 | — | %42,7 | 24 Şub 2020 |
52Planlayın | CVE-2013-2573Kavram kanıtı | A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-tp-link · tl-sc 3130g firmware · CWE-78 | Kritik9,8 | — | %42,2 | 29 Oca 2020 |
51Planlayın | CVE-2021-44827Kavram kanıtı | There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_Exttp-link · archer c20i firmware · CWE-78 | Yüksek8,8 | — | %54,0 | 4 Mar 2022 |
51Planlayın | CVE-2022-25060Kavram kanıtı | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.tp-link · tl-wr840n firmware · CWE-78 | Kritik9,8 | — | %40,2 | 25 Şub 2022 |
50Planlayın | CVE-2017-13772Kavram kanıtı | Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbtp-link · wr940n firmware · CWE-119 | Yüksek8,8 | — | %51,4 | 23 Eki 2017 |
50Planlayın | CVE-2017-8220İstismar yok | TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP requestp-link · c2 firmware · CWE-78 | Kritik9,9 | — | %36,6 | 25 Nis 2017 |
50Planlayın | CVE-2022-25064Kavram kanıtı | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddrtp-link · tl-wr840n firmware · CWE-78 | Kritik9,8 | — | %36,5 | 25 Şub 2022 |
49Planlayın | CVE-2023-36355Kavram kanıtı | TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm.tp-link · tl-wr940n firmware · CWE-120 | Kritik9,9 | — | %31,7 | 22 Haz 2023 |
48Planlayın | CVE-2020-35576Kavram kanıtı | A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticatetp-link · tl-wr841n firmware · CWE-78 | Yüksek8,8 | — | %42,3 | 26 Oca 2021 |
47Planlayın | CVE-2020-10882Silahlaştırılmış | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: tp-link · ac1750 firmware · CWE-78 | Yüksek8,8 | — | %41,4 | 25 Mar 2020 |
- CVE-2023-138995Hemen
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form o
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100tp-link · archer ax21 firmware15 Mar 2023
- CVE-2015-303585Hemen
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0)
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %84tp-link · tl-wr741nd firmware21 Nis 2015
- CVE-2023-3353877Bu hafta
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %42tp-link · tl-wr940n firmware7 Haz 2023
- CVE-2025-937774Bu hafta
Authenticated RCE via Parental Control command injection
YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %34tp-link · tl-wr841n firmware29 Ağu 2025
- CVE-2020-2436371Bu hafta
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %21tp-link · tl-wa855re firmware31 Ağu 2020
- CVE-2022-3786063Bu hafta
The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection v
KritikCVSS 9,8İstismar yokEPSS %80tp-link · m7350 firmware12 Eyl 2022
- CVE-2021-4165362Bu hafta
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution
KritikCVSS 9,8Kavram kanıtıEPSS %76tp-link · tl-wr840n firmware13 Kas 2021
- CVE-2020-2834762Bu hafta
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter.
KritikCVSS 9,8SilahlaştırılmışEPSS %75tp-link · ac1750 firmware8 Kas 2020
- CVE-2013-257862Bu hafta
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware L
KritikCVSS 10,0SilahlaştırılmışEPSS %74tp-link · tl-sc313011 Eki 2013
- CVE-2021-404561Bu hafta
TP-LINK Tapo C200 remote code execution vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %72tp-link · tapo c200 firmware10 Mar 2022
- CVE-2023-5022461Bu hafta
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %16tp-link · tl-wr841n firmware2 May 2024
- CVE-2018-1171459Planlayın
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0
KritikCVSS 9,8Kavram kanıtıEPSS %68tp-link · tl-wr840n firmware4 Haz 2018
- CVE-2020-1210957Planlayın
Certain TP-Link devices allow Command Injection.
YüksekCVSS 8,8SilahlaştırılmışEPSS %74tp-link · nc200 firmware4 May 2020
- CVE-2022-2506157Planlayın
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
KritikCVSS 9,8Kavram kanıtıEPSS %59tp-link · tl-wr840n firmware25 Şub 2022
- CVE-2012-568752Planlayın
Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.
YüksekCVSS 7,8SilahlaştırılmışEPSS %69tp-link · tl-wr841n1 Kas 2012
- CVE-2020-937452Planlayın
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker
KritikCVSS 9,8Kavram kanıtıEPSS %43tp-link · tl-wr849n firmware24 Şub 2020
- CVE-2013-257352Planlayın
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-
KritikCVSS 9,8Kavram kanıtıEPSS %42tp-link · tl-sc 3130g firmware29 Oca 2020
- CVE-2021-4482751Planlayın
There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_Ext
YüksekCVSS 8,8Kavram kanıtıEPSS %54tp-link · archer c20i firmware4 Mar 2022
- CVE-2022-2506051Planlayın
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
KritikCVSS 9,8Kavram kanıtıEPSS %40tp-link · tl-wr840n firmware25 Şub 2022
- CVE-2017-1377250Planlayın
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arb
YüksekCVSS 8,8Kavram kanıtıEPSS %51tp-link · wr940n firmware23 Eki 2017
- CVE-2017-822050Planlayın
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP reques
KritikCVSS 9,9İstismar yokEPSS %37tp-link · c2 firmware25 Nis 2017
- CVE-2022-2506450Planlayın
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr
KritikCVSS 9,8Kavram kanıtıEPSS %36tp-link · tl-wr840n firmware25 Şub 2022
- CVE-2023-3635549Planlayın
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm.
KritikCVSS 9,9Kavram kanıtıEPSS %32tp-link · tl-wr940n firmware22 Haz 2023
- CVE-2020-3557648Planlayın
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticate
YüksekCVSS 8,8Kavram kanıtıEPSS %42tp-link · tl-wr841n firmware26 Oca 2021
- CVE-2020-1088247Planlayın
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver:
YüksekCVSS 8,8SilahlaştırılmışEPSS %41tp-link · ac1750 firmware25 Mar 2020