Vulnerability index

Browse CVEs

510 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tapo P110 Firmware HIGH 7.5
CVE-2026-15314

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insu…

Fix: 1.1.4+
Fix from $1,950 2026-08-04
Omada Fusion 2.5g Firmware MEDIUM 5.9
CVE-2025-15631

A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide…

No fix yet
Fix from $1,600 2026-08-03
Omada Oc200 V3 Firmware HIGH 7.5
CVE-2025-15627

A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect …

No fix yet
Fix from $1,950 2026-08-03
Omada Oc200 V3 Firmware HIGH 7.5
CVE-2025-15628

Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. …

No fix yet
Fix from $1,950 2026-08-03
Omada Oc200 V3 Firmware HIGH 7.5
CVE-2025-15629

A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and m…

No fix yet
Fix from $1,950 2026-08-03
Omada Oc200 V3 Firmware MEDIUM 5.9
CVE-2025-15630

A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a…

No fix yet
Fix from $1,600 2026-08-03
Omada Oc200 V3 Firmware MEDIUM 5.9
CVE-2025-15544

A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management ar…

No fix yet
Fix from $1,600 2026-08-03
Omada Fusion 2.5g Firmware MEDIUM 6.5
CVE-2025-9291

A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification d…

No fix yet
Fix from $1,600 2026-08-03
Archer Axe75 Firmware HIGH 8.0
CVE-2026-9044

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated atta…

Fix: 1.5.6+
Fix from $1,950 2026-07-31
Kasa Ec71 Firmware MEDIUM 5.3
CVE-2026-9770

Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.  An att…

Fix: 2.4.0+
Fix from $1,600 2026-07-15
Kasa Ec70 Firmware MEDIUM 6.5
CVE-2026-13230

An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive …

Fix: 2.4.1+
Fix from $1,600 2026-07-15
Deco M5 Firmware MEDIUM 6.7
CVE-2026-5040

TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compro…

Fix: 1.9.4+
Fix from $1,600 2026-07-14
Archer Vx1800v Firmware HIGH 8.8
CVE-2026-15428

An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent att…

Fix: 0.16.0+
Fix from $1,950 2026-07-14
Archer Vx1800v Firmware HIGH 8.8
CVE-2026-15429

A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may…

Fix: 0.16.0+
Fix from $1,950 2026-07-14
Archer Vx1800v Firmware HIGH 8.1
CVE-2026-15427

An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and …

Fix: 0.16.0+
Fix from $1,950 2026-07-14
Tl Wr841n Firmware MEDIUM 6.5
CVE-2026-9105

An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated a…

Fix: 14_260518+
Fix from $1,600 2026-06-29
Tapo C200 Firmware MEDIUM 6.5
CVE-2026-12760

A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fra…

Mitigation only
Fix from $1,600 2026-06-24
Tl Wr940n Firmware HIGH 7.2
CVE-2026-11409

An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of us…

Fix: 260528+
Fix from $1,950 2026-06-17
Tl Wr940n Firmware HIGH 7.2
CVE-2026-11410

An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper saniti…

Fix: 260528+
Fix from $1,950 2026-06-17
Tapo C110 Firmware HIGH 8.1
CVE-2026-6250

An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  External…

Fix: 1.5.4+
Fix from $1,950 2026-06-11
Tapo C520ws Firmware MEDIUM 6.5
CVE-2026-8714

A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper handling of syntactically invalid inp…

Fix: 1.2.6+
Fix from $1,600 2026-06-05
Tapo C200 Firmware MEDIUM 6.5
CVE-2026-1871

TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header f…

Mitigation only
Fix from $1,600 2026-06-02
Tapo L535e Firmware HIGH 7.5
CVE-2026-34126

TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the ini…

Mitigation only
Fix from $1,950 2026-05-28
Archer C64 Firmware HIGH 8.8
CVE-2026-8697

Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication …

Mitigation only
Fix from $1,950 2026-05-28
Archer Be450 Firmware HIGH 7.2
CVE-2026-5509

An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary…

Fix: 1.3.0+
Fix from $1,950 2026-05-27
Re305 Firmware HIGH 8.8
CVE-2026-3294

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a l…

Fix: 20260429 / 20260515+
Fix from $1,950 2026-05-22
Tl Wr841n Firmware HIGH 8.8
CVE-2026-5039

TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default web management credentials, …

Fix: 231120+
Fix from $1,950 2026-04-23
Archer C7 Firmware HIGH 8.8
CVE-2026-5363

Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interfa…

Fix: 1.2.1+
Fix from $1,950 2026-04-16
Archer Ax53 Firmware HIGH 8.0
CVE-2026-30814

A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation…

Fix: 1.7.1+
Fix from $1,950 2026-04-08
Archer Ax53 Firmware HIGH 8.0
CVE-2026-30815

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system c…

Fix: 1.7.1+
Fix from $1,950 2026-04-08