Skip to content
Noroxi

TP-Link records

554 published records for vendor tp-link.

All records

554 records
  • TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form o

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    tp-link · archer ax21 firmwareMar 15, 2023

  • Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0)

    HighCVSS 7.5KEVWeaponizedEPSS 84%

    tp-link · tl-wr741nd firmwareApr 21, 2015

  • CVE-2023-33538
    77This week

    TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component

    HighCVSS 8.8KEVWeaponizedEPSS 42%

    tp-link · tl-wr940n firmwareJun 7, 2023

  • CVE-2025-9377
    75This week

    Authenticated RCE via Parental Control command injection

    HighCVSS 8.6KEVWeaponizedEPSS 36%

    tp-link · tl-wr841n firmwareAug 29, 2025

  • CVE-2020-24363
    71This week

    TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request

    HighCVSS 8.8KEVWeaponizedEPSS 21%

    tp-link · tl-wa855re firmwareAug 31, 2020

  • CVE-2022-37860
    63This week

    The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection v

    CriticalCVSS 9.8No exploitEPSS 80%

    tp-link · m7350 firmwareSep 12, 2022

  • CVE-2021-41653
    62This week

    The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution

    CriticalCVSS 9.8Proof of conceptEPSS 76%

    tp-link · tl-wr840n firmwareNov 13, 2021

  • CVE-2020-28347
    62This week

    tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter.

    CriticalCVSS 9.8WeaponizedEPSS 75%

    tp-link · ac1750 firmwareNov 8, 2020

  • CVE-2013-2578
    62This week

    cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware L

    CriticalCVSS 10.0WeaponizedEPSS 74%

    tp-link · tl-sc3130Oct 11, 2013

  • CVE-2021-4045
    61This week

    TP-LINK Tapo C200 remote code execution vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 72%

    tp-link · tapo c200 firmwareMar 10, 2022

  • CVE-2023-50224
    61This week

    TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability

    MediumCVSS 6.5KEVWeaponizedEPSS 16%

    tp-link · tl-wr841n firmwareMay 2, 2024

  • An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0

    CriticalCVSS 9.8Proof of conceptEPSS 68%

    tp-link · tl-wr840n firmwareJun 4, 2018

  • Certain TP-Link devices allow Command Injection.

    HighCVSS 8.8WeaponizedEPSS 74%

    tp-link · nc200 firmwareMay 4, 2020

  • TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

    CriticalCVSS 9.8Proof of conceptEPSS 59%

    tp-link · tl-wr840n firmwareFeb 25, 2022

  • Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.

    HighCVSS 7.8WeaponizedEPSS 69%

    tp-link · tl-wr841nNov 1, 2012

  • On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker

    CriticalCVSS 9.8Proof of conceptEPSS 43%

    tp-link · tl-wr849n firmwareFeb 24, 2020

  • A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-

    CriticalCVSS 9.8Proof of conceptEPSS 42%

    tp-link · tl-sc 3130g firmwareJan 29, 2020

  • There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_Ext

    HighCVSS 8.8Proof of conceptEPSS 54%

    tp-link · archer c20i firmwareMar 4, 2022

  • TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

    CriticalCVSS 9.8Proof of conceptEPSS 40%

    tp-link · tl-wr840n firmwareFeb 25, 2022

  • Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arb

    HighCVSS 8.8Proof of conceptEPSS 51%

    tp-link · wr940n firmwareOct 23, 2017

  • TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP reques

    CriticalCVSS 9.9No exploitEPSS 37%

    tp-link · c2 firmwareApr 25, 2017

  • TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr

    CriticalCVSS 9.8Proof of conceptEPSS 36%

    tp-link · tl-wr840n firmwareFeb 25, 2022

  • TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm.

    CriticalCVSS 9.9Proof of conceptEPSS 32%

    tp-link · tl-wr940n firmwareJun 22, 2023

  • A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticate

    HighCVSS 8.8Proof of conceptEPSS 42%

    tp-link · tl-wr841n firmwareJan 26, 2021

  • This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver:

    HighCVSS 8.8WeaponizedEPSS 41%

    tp-link · ac1750 firmwareMar 25, 2020