Tp-Link
468 known vulnerabilities
Top Products
A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allo
A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to imprope
The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out
A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5
A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated a
A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (
Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be execute
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated s
A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed u
User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbit
On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending
On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters
A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP ser
An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on
The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is get
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tdpserver modules) allows adjacent attackers to ca
SSH Hostkey misconfiguration vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows attackers to obtain de
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
An authenticated user with high privileges may trigger a denial‑of‑service condition in TP-Link Archer BE230 v1.2 by res
A lack of proper input validation in the HTTP processing path in TP-Link Archer BE230 v1.2 (web modules) may allow a cra
A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN clie
A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restora
A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration modu
A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the
A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attack
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attack
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attack
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjace
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent
An authenticated buffer handling flaw in TP-Link VIGI C385 V1 Web API lacking input sanitization, may allow memory corru
Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application
Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem co
Improper handling of exceptional conditions in VX800v v1.0 in SIP processing allows an attacker to flood the device with
Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic
A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force
The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such
By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core syste
The HTTP parser of Tapo C210 v3, C220 v1 and C520WS v2 cameras improperly handles requests containing an excessively lon
The Tapo C100 v5, C220 v1 and C520WS v2 cameras’ HTTP service does not safely handle POST requests containing an excessi
Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests t
Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypa
Frequently Asked Questions
How many CVEs affect Tp-Link?
Tp-Link has 468 CVE records in our database, including 24 critical and 256 high severity vulnerabilities.
What are the most severe Tp-Link vulnerabilities?
Tp-Link has 24 critical severity (CVSS 9.0+) and 256 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Tp-Link vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Tp-Link products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Tp-Link Vulnerabilities
CyberStrike scans your infrastructure for Tp-Link vulnerabilities and provides real-time remediation guidance.
Get Started