Tp-Link
2,304 known vulnerabilities
Top Products
TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monit
TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 username and password are sent via the cookie.
TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). Al
TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface tha
TP-Link Archer C1200 firmware version 1.13 Build 2018/01/24 rel.52299 EU has a XSS vulnerability allowing a remote attac
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch
Buffer Overflow in TP-Link WR2041 v1 firmware for the TL-WR2041+ router allows remote attackers to cause a Denial-of-Ser
In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, T
TP-Link TL-WR802N(US), Archer_C50v5_US v4_200 <= 2020.06 contains a buffer overflow vulnerability in the httpd process i
This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 prior to Archer C7(US)_V5_210
Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless A
TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,
In the management interface on TP-Link Archer C5v 1.7_181221 devices, credentials are sent in a base64 format over clear
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216
oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw s
A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full adminis
UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with
Buffer overflow in in the copy_msg_element function for the devDiscoverHandle server in the TP-Link WR and WDR series, i
httpd on TP-Link TL-WPA4220 devices (hardware versions 2 through 4) allows remote authenticated users to trigger a buffe
httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS com
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the sl
UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)_V5_200721 allows an authenticated admin user, with physi
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to denial-of-s
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to conduct per
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to bypass auth
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate pri
On TP-Link TL-WR740N v4 and TL-WR740ND v4 devices, an attacker with access to the admin panel can inject HTML code and c
TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.
This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA85
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220
Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.
TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.p
Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304,
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated
TP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 thro
TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive informatio
This vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmw
This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 r
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firm
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firm
This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer
This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firm
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploit
The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the
TP-LINK TL-WR1043ND V1_120405 devices contain an unspecified denial of service vulnerability.
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cam
Frequently Asked Questions
How many CVEs affect Tp-Link?
Tp-Link has 2,304 CVE records in our database, including 313 critical and 1536 high severity vulnerabilities. 5 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Tp-Link vulnerabilities?
Tp-Link has 313 critical severity (CVSS 9.0+) and 1536 high severity (CVSS 7.0-8.9) vulnerabilities. 5 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Tp-Link vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Tp-Link products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Tp-Link Vulnerabilities
CyberStrike scans your infrastructure for Tp-Link vulnerabilities and provides real-time remediation guidance.
Get Started