TP-Link records
554 published records for vendor tp-link.
Researcher profile
- Entered KEV
- 6 · 1.1%
- Weaponized
- 13 · 2.3%
- Pre-auth RCE
- 84
- With a fix record
- 2.3%
- Median publish → KEV
- 615 days
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')95
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')42
- CWE-787 Out-of-bounds Write36
- CWE-121 Stack-based Buffer Overflow34
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')22
- CWE-20 Improper Input Validation22
The weakness classes this vendor ships most often: where to look.
CWEAll records
554 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2023-1389Weaponized | TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form otp-link · archer ax21 firmware · CWE-77 | High8.8 | KEV | 100.0% | Mar 15, 2023 |
85Now | CVE-2015-3035Weaponized | Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0)tp-link · tl-wr741nd firmware · CWE-22 | High7.5 | KEV | 83.9% | Apr 21, 2015 |
77This week | CVE-2023-33538Weaponized | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the componenttp-link · tl-wr940n firmware · CWE-77 | High8.8 | KEV | 41.6% | Jun 7, 2023 |
75This week | CVE-2025-9377Weaponized | Authenticated RCE via Parental Control command injectiontp-link · tl-wr841n firmware · CWE-78 | High8.6 | KEV | 35.8% | Aug 29, 2025 |
71This week | CVE-2020-24363Weaponized | TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request tp-link · tl-wa855re firmware · CWE-306 | High8.8 | KEV | 20.7% | Aug 31, 2020 |
63This week | CVE-2022-37860No exploit | The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vtp-link · m7350 firmware · CWE-78 | Critical9.8 | — | 80.4% | Sep 12, 2022 |
62This week | CVE-2021-41653Proof of concept | The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code executiontp-link · tl-wr840n firmware · CWE-94 | Critical9.8 | — | 76.0% | Nov 13, 2021 |
62This week | CVE-2020-28347Weaponized | tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter.tp-link · ac1750 firmware · CWE-78 | Critical9.8 | — | 75.4% | Nov 8, 2020 |
62This week | CVE-2013-2578Weaponized | cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware Ltp-link · tl-sc3130 · CWE-78 | Critical10.0 | — | 73.7% | Oct 11, 2013 |
61This week | CVE-2021-4045Proof of concept | TP-LINK Tapo C200 remote code execution vulnerabilitytp-link · tapo c200 firmware · CWE-77 | Critical9.8 | — | 72.4% | Mar 10, 2022 |
61This week | CVE-2023-50224Weaponized | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerabilitytp-link · tl-wr841n firmware · CWE-290 | Medium6.5 | KEV | 15.6% | May 2, 2024 |
59Plan | CVE-2018-11714Proof of concept | An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0tp-link · tl-wr840n firmware · CWE-384 | Critical9.8 | — | 68.1% | Jun 4, 2018 |
57Plan | CVE-2020-12109Weaponized | Certain TP-Link devices allow Command Injection.tp-link · nc200 firmware · CWE-78 | High8.8 | — | 74.3% | May 4, 2020 |
57Plan | CVE-2022-25061Proof of concept | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.tp-link · tl-wr840n firmware · CWE-78 | Critical9.8 | — | 58.7% | Feb 25, 2022 |
52Plan | CVE-2012-5687Weaponized | Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.tp-link · tl-wr841n · CWE-22 | High7.8 | — | 68.7% | Nov 1, 2012 |
52Plan | CVE-2020-9374Proof of concept | On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker tp-link · tl-wr849n firmware · CWE-78 | Critical9.8 | — | 42.7% | Feb 24, 2020 |
52Plan | CVE-2013-2573Proof of concept | A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-tp-link · tl-sc 3130g firmware · CWE-78 | Critical9.8 | — | 42.2% | Jan 29, 2020 |
51Plan | CVE-2021-44827Proof of concept | There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_Exttp-link · archer c20i firmware · CWE-78 | High8.8 | — | 54.0% | Mar 4, 2022 |
51Plan | CVE-2022-25060Proof of concept | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.tp-link · tl-wr840n firmware · CWE-78 | Critical9.8 | — | 40.2% | Feb 25, 2022 |
50Plan | CVE-2017-13772Proof of concept | Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbtp-link · wr940n firmware · CWE-119 | High8.8 | — | 51.4% | Oct 23, 2017 |
50Plan | CVE-2017-8220No exploit | TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP requestp-link · c2 firmware · CWE-78 | Critical9.9 | — | 36.6% | Apr 25, 2017 |
50Plan | CVE-2022-25064Proof of concept | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddrtp-link · tl-wr840n firmware · CWE-78 | Critical9.8 | — | 36.5% | Feb 25, 2022 |
49Plan | CVE-2023-36355Proof of concept | TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm.tp-link · tl-wr940n firmware · CWE-120 | Critical9.9 | — | 31.7% | Jun 22, 2023 |
48Plan | CVE-2020-35576Proof of concept | A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticatetp-link · tl-wr841n firmware · CWE-78 | High8.8 | — | 42.3% | Jan 26, 2021 |
47Plan | CVE-2020-10882Weaponized | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: tp-link · ac1750 firmware · CWE-78 | High8.8 | — | 41.4% | Mar 25, 2020 |
- CVE-2023-138995Now
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form o
HighCVSS 8.8KEVWeaponizedEPSS 100%tp-link · archer ax21 firmwareMar 15, 2023
- CVE-2015-303585Now
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0)
HighCVSS 7.5KEVWeaponizedEPSS 84%tp-link · tl-wr741nd firmwareApr 21, 2015
- CVE-2023-3353877This week
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component
HighCVSS 8.8KEVWeaponizedEPSS 42%tp-link · tl-wr940n firmwareJun 7, 2023
- CVE-2025-937775This week
Authenticated RCE via Parental Control command injection
HighCVSS 8.6KEVWeaponizedEPSS 36%tp-link · tl-wr841n firmwareAug 29, 2025
- CVE-2020-2436371This week
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request
HighCVSS 8.8KEVWeaponizedEPSS 21%tp-link · tl-wa855re firmwareAug 31, 2020
- CVE-2022-3786063This week
The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection v
CriticalCVSS 9.8No exploitEPSS 80%tp-link · m7350 firmwareSep 12, 2022
- CVE-2021-4165362This week
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution
CriticalCVSS 9.8Proof of conceptEPSS 76%tp-link · tl-wr840n firmwareNov 13, 2021
- CVE-2020-2834762This week
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter.
CriticalCVSS 9.8WeaponizedEPSS 75%tp-link · ac1750 firmwareNov 8, 2020
- CVE-2013-257862This week
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware L
CriticalCVSS 10.0WeaponizedEPSS 74%tp-link · tl-sc3130Oct 11, 2013
- CVE-2021-404561This week
TP-LINK Tapo C200 remote code execution vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 72%tp-link · tapo c200 firmwareMar 10, 2022
- CVE-2023-5022461This week
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability
MediumCVSS 6.5KEVWeaponizedEPSS 16%tp-link · tl-wr841n firmwareMay 2, 2024
- CVE-2018-1171459Plan
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0
CriticalCVSS 9.8Proof of conceptEPSS 68%tp-link · tl-wr840n firmwareJun 4, 2018
- CVE-2020-1210957Plan
Certain TP-Link devices allow Command Injection.
HighCVSS 8.8WeaponizedEPSS 74%tp-link · nc200 firmwareMay 4, 2020
- CVE-2022-2506157Plan
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
CriticalCVSS 9.8Proof of conceptEPSS 59%tp-link · tl-wr840n firmwareFeb 25, 2022
- CVE-2012-568752Plan
Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.
HighCVSS 7.8WeaponizedEPSS 69%tp-link · tl-wr841nNov 1, 2012
- CVE-2020-937452Plan
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker
CriticalCVSS 9.8Proof of conceptEPSS 43%tp-link · tl-wr849n firmwareFeb 24, 2020
- CVE-2013-257352Plan
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-
CriticalCVSS 9.8Proof of conceptEPSS 42%tp-link · tl-sc 3130g firmwareJan 29, 2020
- CVE-2021-4482751Plan
There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_Ext
HighCVSS 8.8Proof of conceptEPSS 54%tp-link · archer c20i firmwareMar 4, 2022
- CVE-2022-2506051Plan
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
CriticalCVSS 9.8Proof of conceptEPSS 40%tp-link · tl-wr840n firmwareFeb 25, 2022
- CVE-2017-1377250Plan
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arb
HighCVSS 8.8Proof of conceptEPSS 51%tp-link · wr940n firmwareOct 23, 2017
- CVE-2017-822050Plan
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP reques
CriticalCVSS 9.9No exploitEPSS 37%tp-link · c2 firmwareApr 25, 2017
- CVE-2022-2506450Plan
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr
CriticalCVSS 9.8Proof of conceptEPSS 36%tp-link · tl-wr840n firmwareFeb 25, 2022
- CVE-2023-3635549Plan
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm.
CriticalCVSS 9.9Proof of conceptEPSS 32%tp-link · tl-wr940n firmwareJun 22, 2023
- CVE-2020-3557648Plan
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticate
HighCVSS 8.8Proof of conceptEPSS 42%tp-link · tl-wr841n firmwareJan 26, 2021
- CVE-2020-1088247Plan
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver:
HighCVSS 8.8WeaponizedEPSS 41%tp-link · ac1750 firmwareMar 25, 2020