Записи TP-Link
554 опубликованных записей вендора tp-link.
Профиль для исследователя
- Попали в KEV
- 6 · 1,1 %
- С эксплойтом
- 13 · 2,3 %
- Pre-auth RCE
- 84
- С записью об исправлении
- 2,3 %
- Медиана: публикация → KEV
- 615 дн.
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')95
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')42
- CWE-787 Out-of-bounds Write36
- CWE-121 Stack-based Buffer Overflow34
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')22
- CWE-20 Improper Input Validation22
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
554 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
95Срочно | CVE-2023-1389Готовый эксплойт | TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form otp-link · archer ax21 firmware · CWE-77 | Высокая8,8 | KEV | 100,0 % | 15 мар. 2023 г. |
85Срочно | CVE-2015-3035Готовый эксплойт | Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0)tp-link · tl-wr741nd firmware · CWE-22 | Высокая7,5 | KEV | 83,9 % | 21 апр. 2015 г. |
77На этой неделе | CVE-2023-33538Готовый эксплойт | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the componenttp-link · tl-wr940n firmware · CWE-77 | Высокая8,8 | KEV | 41,6 % | 7 июн. 2023 г. |
74На этой неделе | CVE-2025-9377Готовый эксплойт | Authenticated RCE via Parental Control command injectiontp-link · tl-wr841n firmware · CWE-78 | Высокая8,6 | KEV | 33,5 % | 29 авг. 2025 г. |
71На этой неделе | CVE-2020-24363Готовый эксплойт | TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request tp-link · tl-wa855re firmware · CWE-306 | Высокая8,8 | KEV | 20,7 % | 31 авг. 2020 г. |
63На этой неделе | CVE-2022-37860Эксплойта нет | The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vtp-link · m7350 firmware · CWE-78 | Критическая9,8 | — | 80,0 % | 12 сент. 2022 г. |
62На этой неделе | CVE-2021-41653Proof of concept | The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code executiontp-link · tl-wr840n firmware · CWE-94 | Критическая9,8 | — | 76,0 % | 13 нояб. 2021 г. |
62На этой неделе | CVE-2020-28347Готовый эксплойт | tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter.tp-link · ac1750 firmware · CWE-78 | Критическая9,8 | — | 75,4 % | 8 нояб. 2020 г. |
62На этой неделе | CVE-2013-2578Готовый эксплойт | cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware Ltp-link · tl-sc3130 · CWE-78 | Критическая10,0 | — | 73,7 % | 11 окт. 2013 г. |
61На этой неделе | CVE-2021-4045Proof of concept | TP-LINK Tapo C200 remote code execution vulnerabilitytp-link · tapo c200 firmware · CWE-77 | Критическая9,8 | — | 72,4 % | 10 мар. 2022 г. |
61На этой неделе | CVE-2023-50224Готовый эксплойт | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerabilitytp-link · tl-wr841n firmware · CWE-290 | Средняя6,5 | KEV | 15,6 % | 2 мая 2024 г. |
59В плане | CVE-2018-11714Proof of concept | An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0tp-link · tl-wr840n firmware · CWE-384 | Критическая9,8 | — | 68,1 % | 4 июн. 2018 г. |
57В плане | CVE-2020-12109Готовый эксплойт | Certain TP-Link devices allow Command Injection.tp-link · nc200 firmware · CWE-78 | Высокая8,8 | — | 74,3 % | 4 мая 2020 г. |
57В плане | CVE-2022-25061Proof of concept | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.tp-link · tl-wr840n firmware · CWE-78 | Критическая9,8 | — | 58,7 % | 25 февр. 2022 г. |
52В плане | CVE-2012-5687Готовый эксплойт | Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.tp-link · tl-wr841n · CWE-22 | Высокая7,8 | — | 68,7 % | 1 нояб. 2012 г. |
52В плане | CVE-2020-9374Proof of concept | On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker tp-link · tl-wr849n firmware · CWE-78 | Критическая9,8 | — | 42,7 % | 24 февр. 2020 г. |
52В плане | CVE-2013-2573Proof of concept | A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-tp-link · tl-sc 3130g firmware · CWE-78 | Критическая9,8 | — | 42,2 % | 29 янв. 2020 г. |
51В плане | CVE-2021-44827Proof of concept | There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_Exttp-link · archer c20i firmware · CWE-78 | Высокая8,8 | — | 54,0 % | 4 мар. 2022 г. |
51В плане | CVE-2022-25060Proof of concept | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.tp-link · tl-wr840n firmware · CWE-78 | Критическая9,8 | — | 40,2 % | 25 февр. 2022 г. |
50В плане | CVE-2017-13772Proof of concept | Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbtp-link · wr940n firmware · CWE-119 | Высокая8,8 | — | 51,4 % | 23 окт. 2017 г. |
50В плане | CVE-2017-8220Эксплойта нет | TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP requestp-link · c2 firmware · CWE-78 | Критическая9,9 | — | 36,6 % | 25 апр. 2017 г. |
50В плане | CVE-2022-25064Proof of concept | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddrtp-link · tl-wr840n firmware · CWE-78 | Критическая9,8 | — | 36,5 % | 25 февр. 2022 г. |
49В плане | CVE-2023-36355Proof of concept | TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm.tp-link · tl-wr940n firmware · CWE-120 | Критическая9,9 | — | 31,7 % | 22 июн. 2023 г. |
48В плане | CVE-2020-35576Proof of concept | A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticatetp-link · tl-wr841n firmware · CWE-78 | Высокая8,8 | — | 42,3 % | 26 янв. 2021 г. |
47В плане | CVE-2020-10882Готовый эксплойт | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: tp-link · ac1750 firmware · CWE-78 | Высокая8,8 | — | 41,4 % | 25 мар. 2020 г. |
- CVE-2023-138995Срочно
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form o
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 100 %tp-link · archer ax21 firmware15 мар. 2023 г.
- CVE-2015-303585Срочно
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0)
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 84 %tp-link · tl-wr741nd firmware21 апр. 2015 г.
- CVE-2023-3353877На этой неделе
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 42 %tp-link · tl-wr940n firmware7 июн. 2023 г.
- CVE-2025-937774На этой неделе
Authenticated RCE via Parental Control command injection
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 34 %tp-link · tl-wr841n firmware29 авг. 2025 г.
- CVE-2020-2436371На этой неделе
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 21 %tp-link · tl-wa855re firmware31 авг. 2020 г.
- CVE-2022-3786063На этой неделе
The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection v
КритическаяCVSS 9,8Эксплойта нетEPSS 80 %tp-link · m7350 firmware12 сент. 2022 г.
- CVE-2021-4165362На этой неделе
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution
КритическаяCVSS 9,8Proof of conceptEPSS 76 %tp-link · tl-wr840n firmware13 нояб. 2021 г.
- CVE-2020-2834762На этой неделе
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter.
КритическаяCVSS 9,8Готовый эксплойтEPSS 75 %tp-link · ac1750 firmware8 нояб. 2020 г.
- CVE-2013-257862На этой неделе
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware L
КритическаяCVSS 10,0Готовый эксплойтEPSS 74 %tp-link · tl-sc313011 окт. 2013 г.
- CVE-2021-404561На этой неделе
TP-LINK Tapo C200 remote code execution vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 72 %tp-link · tapo c200 firmware10 мар. 2022 г.
- CVE-2023-5022461На этой неделе
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 16 %tp-link · tl-wr841n firmware2 мая 2024 г.
- CVE-2018-1171459В плане
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0
КритическаяCVSS 9,8Proof of conceptEPSS 68 %tp-link · tl-wr840n firmware4 июн. 2018 г.
- CVE-2020-1210957В плане
Certain TP-Link devices allow Command Injection.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 74 %tp-link · nc200 firmware4 мая 2020 г.
- CVE-2022-2506157В плане
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
КритическаяCVSS 9,8Proof of conceptEPSS 59 %tp-link · tl-wr840n firmware25 февр. 2022 г.
- CVE-2012-568752В плане
Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.
ВысокаяCVSS 7,8Готовый эксплойтEPSS 69 %tp-link · tl-wr841n1 нояб. 2012 г.
- CVE-2020-937452В плане
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker
КритическаяCVSS 9,8Proof of conceptEPSS 43 %tp-link · tl-wr849n firmware24 февр. 2020 г.
- CVE-2013-257352В плане
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-
КритическаяCVSS 9,8Proof of conceptEPSS 42 %tp-link · tl-sc 3130g firmware29 янв. 2020 г.
- CVE-2021-4482751В плане
There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_Ext
ВысокаяCVSS 8,8Proof of conceptEPSS 54 %tp-link · archer c20i firmware4 мар. 2022 г.
- CVE-2022-2506051В плане
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
КритическаяCVSS 9,8Proof of conceptEPSS 40 %tp-link · tl-wr840n firmware25 февр. 2022 г.
- CVE-2017-1377250В плане
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arb
ВысокаяCVSS 8,8Proof of conceptEPSS 51 %tp-link · wr940n firmware23 окт. 2017 г.
- CVE-2017-822050В плане
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP reques
КритическаяCVSS 9,9Эксплойта нетEPSS 37 %tp-link · c2 firmware25 апр. 2017 г.
- CVE-2022-2506450В плане
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr
КритическаяCVSS 9,8Proof of conceptEPSS 36 %tp-link · tl-wr840n firmware25 февр. 2022 г.
- CVE-2023-3635549В плане
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm.
КритическаяCVSS 9,9Proof of conceptEPSS 32 %tp-link · tl-wr940n firmware22 июн. 2023 г.
- CVE-2020-3557648В плане
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticate
ВысокаяCVSS 8,8Proof of conceptEPSS 42 %tp-link · tl-wr841n firmware26 янв. 2021 г.
- CVE-2020-1088247В плане
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver:
ВысокаяCVSS 8,8Готовый эксплойтEPSS 41 %tp-link · ac1750 firmware25 мар. 2020 г.