Tp-Link
468 known vulnerabilities
Top Products
Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HT
A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing al
A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t
A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communicati
Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between contr
A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to
A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials assoc
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certif
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an
Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is s
An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechan
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the passwo
A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling
An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain na
An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insuf
An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v
A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to
An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR9
An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due t
An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of use
A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper handling
TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validat
A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG
TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service all
An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an admin
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjac
In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user i
TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform u
TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default
Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery
An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjac
An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated ad
An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent
A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attac
A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic.
A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling c
An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v
A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing of
A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when
A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST bod
The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of
The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-boun
A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitiz
A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables
Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600
Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600
A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoin
This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe
Frequently Asked Questions
How many CVEs affect Tp-Link?
Tp-Link has 468 CVE records in our database, including 24 critical and 256 high severity vulnerabilities.
What are the most severe Tp-Link vulnerabilities?
Tp-Link has 24 critical severity (CVSS 9.0+) and 256 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Tp-Link vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Tp-Link products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Tp-Link Vulnerabilities
CyberStrike scans your infrastructure for Tp-Link vulnerabilities and provides real-time remediation guidance.
Get Started