Vulnerability index

Browse CVEs

325 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Tl Wr902ac Firmware CRITICAL 9.8
CVE-2022-25074EPSS 13%

TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows un…

No fix yet
Fix from $2,300 2022-02-24
Tl Wa850re Firmware CRITICAL 9.8
CVE-2022-22922

TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable session keys, allowing attack…

No fix yet
Fix from $2,300 2022-02-18
Tl Wr841n Firmware CRITICAL 9.8
CVE-2022-0162

The vulnerability exists in TP-Link TL-WR841N V11 3.16.9 Build 160325 Rel.62500n wireless router due to transmission of authentication information in…

Mitigation only
Fix from $2,300 2022-02-09
Wn886n Firmware MEDIUM 6.5
CVE-2021-44864EPSS 10%

TP-Link WR886N 3.0 1.0.1 Build 150127 Rel.34123n is vulnerable to Buffer Overflow. Authenticated attackers can crash router httpd services via /userR…

No fix yet
Fix from $1,600 2022-02-08
Archer C90 Firmware CRITICAL 9.8
CVE-2021-35003EPSS 8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer C90 1.0.6 Build 20200114 rel.73164(5…

Mitigation only
Fix from $2,300 2022-01-21
Tl Wa1201 Firmware CRITICAL 9.8
CVE-2021-35004EPSS 8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link TL-WA1201 1.0.1 Build 20200709 rel.66244(55…

Mitigation only
Fix from $2,300 2022-01-21
Archer Ax10 Firmware HIGH 7.5
CVE-2021-41451

A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send …

Mitigation only
Fix from $1,950 2021-12-17
Tl Wr840n Firmware CRITICAL 9.8
CVE-2021-41653EPSS 76%

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a cr…

Mitigation only
Fix from $2,300 2021-11-13
Tl Wr840n Firmware MEDIUM 6.4
CVE-2021-29280

In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow

No fix yet
Fix from $1,600 2021-08-19
Tl Wpa4220 Firmware HIGH 7.5
CVE-2021-28857

TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 username and password are sent via the cookie.

No fix yet
Fix from $1,950 2021-06-15
Tl Wpa4220 Firmware MEDIUM 5.5
CVE-2021-28858

TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monitor traffic and capture the co…

No fix yet
Fix from $1,600 2021-06-15
Tl Sg2005 Firmware HIGH 8.8
CVE-2021-31659

TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information i…

Mitigation only
Fix from $1,950 2021-06-10
Tl Sg2005 Firmware HIGH 8.1
CVE-2021-31658

TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface that provides the "device descri…

Mitigation only
Fix from $1,950 2021-06-10
Archer C1200 Firmware MEDIUM 6.1
CVE-2020-17891

TP-Link Archer C1200 firmware version 1.13 Build 2018/01/24 rel.52299 EU has a XSS vulnerability allowing a remote attacker to execute arbitrary code.

No fix yet
Fix from $1,600 2021-05-14
Ac1750 Firmware HIGH 8.0
CVE-2021-27246EPSS 7%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 AC1750 1.0.15 routers. …

Mitigation only
Fix from $1,950 2021-04-14
Tl Wr2041\+ Firmware HIGH 7.5
CVE-2021-26827

Buffer Overflow in TP-Link WR2041 v1 firmware for the TL-WR2041+ router allows remote attackers to cause a Denial-of-Service (DoS) by sending an HTTP…

No fix yet
Fix from $1,950 2021-04-14
Archer A7 Firmware HIGH 8.1
CVE-2021-27245

This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 prior to Archer C7(US)_V5_210125 and Archer A7(US)_V5_2002…

Mitigation only
Fix from $1,950 2021-03-29
Td W9977 Firmware MEDIUM 6.1
CVE-2021-3275

Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers), Access Points, AD…

No fix yet
Fix from $1,600 2021-03-26
Archer C5v Firmware HIGH 7.1
CVE-2021-27209

In the management interface on TP-Link Archer C5v 1.7_181221 devices, credentials are sent in a base64 format over cleartext HTTP.

No fix yet
Fix from $1,950 2021-02-13
Archer C5v Firmware MEDIUM 6.5
CVE-2021-27210

TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,0#0,0,0,0,0,0]0,0 to the /cgi…

No fix yet
Fix from $1,600 2021-02-13
Tl Wr840n Firmware CRITICAL 9.8
CVE-2020-36178EPSS 10%

oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web in…

No fix yet
Fix from $2,300 2021-01-06
Archer C9 Firmware MEDIUM 6.1
CVE-2020-5797

UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with physical access and network …

No fix yet
Fix from $1,600 2020-11-21
Wdr7400 Firmware CRITICAL 9.8
CVE-2020-28877

Buffer overflow in in the copy_msg_element function for the devDiscoverHandle server in the TP-Link WR and WDR series, including WDR7400, WDR7500, WD…

Mitigation only
Fix from $2,300 2020-11-20
Tl Wpa4220 Firmware HIGH 8.8
CVE-2020-24297

httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS commands by sending crafted POST…

No fix yet
Fix from $1,950 2020-11-18
Tl Wpa4220 Firmware MEDIUM 6.5
CVE-2020-28005

httpd on TP-Link TL-WPA4220 devices (hardware versions 2 through 4) allows remote authenticated users to trigger a buffer overflow (causing a denial …

No fix yet
Fix from $1,600 2020-11-18
Archer A7 Firmware MEDIUM 6.2
CVE-2020-5795

UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)_V5_200721 allows an authenticated admin user, with physical access and network access…

No fix yet
Fix from $1,600 2020-11-06
Tl Wa855re Firmware HIGH 8.0
CVE-2020-10916

This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA855RE Firmware Ver: 855rev4-up-…

Mitigation only
Fix from $1,950 2020-05-07
Nc200 Firmware HIGH 8.8
CVE-2020-12109EPSS 74%

Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3…

No fix yet
Fix from $1,950 2020-05-04
Nc260 Firmware HIGH 8.8
CVE-2020-12111EPSS 8%

Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.

No fix yet
Fix from $1,950 2020-05-04
Nc200 Firmware CRITICAL 9.8
CVE-2020-12110EPSS 13%

Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC…

No fix yet
Fix from $2,300 2020-05-04