Tp-Link
2,304 known vulnerabilities
Top Products
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can cras
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can cras
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can cras
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can cras
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets w
TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI.
The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices al
TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking.
On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface a
CSRF exists for all actions in the web interface on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.6
TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote attackers to cause a denial of service (re
Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticat
TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary c
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00
/usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a
TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices allow authenticated remote code execu
TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of
The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows
The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows doe
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Window
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Window
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call t
Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated adminis
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote a
Frequently Asked Questions
How many CVEs affect Tp-Link?
Tp-Link has 2,304 CVE records in our database, including 313 critical and 1536 high severity vulnerabilities. 5 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Tp-Link vulnerabilities?
Tp-Link has 313 critical severity (CVSS 9.0+) and 1536 high severity (CVSS 7.0-8.9) vulnerabilities. 5 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Tp-Link vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Tp-Link products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Tp-Link Vulnerabilities
CyberStrike scans your infrastructure for Tp-Link vulnerabilities and provides real-time remediation guidance.
Get Started