Vulnerability index

Browse CVEs

325 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2017-15624 TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-authtype var… Er5110g Firmware No fix yet Fix from $1,9502018-01-11 HIGH 7.2 CVE-2017-15625 TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-olmode varia… Er5110g Firmware No fix yet Fix from $1,9502018-01-11 HIGH 7.2 CVE-2017-15626 TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-bindif varia… Er5110g Firmware No fix yet Fix from $1,9502018-01-11 MEDIUM 6.8 CVE-2017-17746 Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device w… Tl Sg108e Firmware No fix yet Fix from $1,6002017-12-20 MEDIUM 6.5 CVE-2017-17747 Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, trig… Tl Sg108e Firmware No fix yet Fix from $1,6002017-12-20 MEDIUM 5.4 CVE-2017-17745 Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary … Tl Sg108e Firmware Mitigation only Fix from $1,6002017-12-20 HIGH 8.8 CVE-2017-17757 TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of a… Tl Wvr450l Firmware No fix yet Fix from $1,9502017-12-19 HIGH 8.8 CVE-2017-17758 TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of a… Tl Wvr450l Firmware No fix yet Fix from $1,9502017-12-19 HIGH 8.8 CVE-2017-16957EPSS 6% TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface … Tl Wvr300 Firmware No fix yet Fix from $1,9502017-11-27 HIGH 8.8 CVE-2017-16958 TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bind… Tl Wvr300 Firmware No fix yet Fix from $1,9502017-11-27 HIGH 8.8 CVE-2017-16960 TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bind… Tl Er5510g Mitigation only Fix from $1,9502017-11-27 MEDIUM 6.5 CVE-2017-16959 The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of … Tl Wvr300 Firmware No fix yet Fix from $1,6002017-11-27 HIGH 8.8 CVE-2017-13772EPSS 53% Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary co… Wr940n Firmware No fix yet Fix from $1,9502017-10-23 MEDIUM 6.1 CVE-2017-15291 Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject a… Tl Mr3220 Firmware No fix yet Fix from $1,6002017-10-20 CRITICAL 9.8 CVE-2017-11519 passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random number g… Archer C9 \(2.0\) Firmware No fix yet Fix from $2,3002017-07-21 CRITICAL 9.8 CVE-2017-9466 The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption. T… Wr841n V8 Firmware No fix yet Fix from $2,3002017-06-26 CRITICAL 9.8 CVE-2017-8074 On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadecimal. Thi… Tl Sg108e Firmware No fix yet Fix from $2,3002017-04-23 CRITICAL 9.8 CVE-2017-8075 On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext. This affect… Tl Sg108e Firmware No fix yet Fix from $2,3002017-04-23 CRITICAL 9.8 CVE-2017-8076 On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is deprecated. This affects the 1.1.2 Build 20141017 Rel.… Tl Sg108e Firmware No fix yet Fix from $2,3002017-04-23 HIGH 7.5 CVE-2017-8077 On the TP-Link TL-SG108E 1.0, there is a hard-coded ciphering key (a long string beginning with Ei2HNryt). This affects the 1.1.2 Build 20141017 Rel.… Tl Sg108e Firmware No fix yet Fix from $1,9502017-04-23 MEDIUM 5.3 CVE-2017-8078 On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd). This af… Tl Sg108e Firmware No fix yet Fix from $1,6002017-04-23 HIGH 7.5 CVE-2016-1000009 TP-LINK lost control of two domains, www.tplinklogin.net and tplinkextender.net. Please note that these domains are physically printed on many of the… Tp Link Mitigation only Fix from $1,9502016-10-06 MEDIUM 5.0 CVE-2014-9350EPSS 7% TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a denial of serv… Tl Wr740n Firmware No fix yet Fix from $1,6002014-12-08 HIGH 9.3 CVE-2013-2645 Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_120405 allow remote attackers t… Firmware Mitigation only Fix from $1,9502014-10-06 HIGH 7.5 CVE-2012-2440 The default configuration of the TP-Link 8840T router enables web-based administration on the WAN interface, which allows remote attackers to establi… 8840t Mitigation only Fix from $1,9502012-04-28