Vulnerability index

Browse CVEs

325 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2022-25074EPSS 13% TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows un… Tl Wr902ac Firmware No fix yet Fix from $2,3002022-02-24 CRITICAL 9.8 CVE-2022-22922 TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable session keys, allowing attack… Tl Wa850re Firmware No fix yet Fix from $2,3002022-02-18 CRITICAL 9.8 CVE-2022-0162 The vulnerability exists in TP-Link TL-WR841N V11 3.16.9 Build 160325 Rel.62500n wireless router due to transmission of authentication information in… Tl Wr841n Firmware Mitigation only Fix from $2,3002022-02-09 MEDIUM 6.5 CVE-2021-44864EPSS 10% TP-Link WR886N 3.0 1.0.1 Build 150127 Rel.34123n is vulnerable to Buffer Overflow. Authenticated attackers can crash router httpd services via /userR… Wn886n Firmware No fix yet Fix from $1,6002022-02-08 CRITICAL 9.8 CVE-2021-35003EPSS 8% This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer C90 1.0.6 Build 20200114 rel.73164(5… Archer C90 Firmware Mitigation only Fix from $2,3002022-01-21 CRITICAL 9.8 CVE-2021-35004EPSS 8% This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link TL-WA1201 1.0.1 Build 20200709 rel.66244(55… Tl Wa1201 Firmware Mitigation only Fix from $2,3002022-01-21 HIGH 7.5 CVE-2021-41451 A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send … Archer Ax10 Firmware Mitigation only Fix from $1,9502021-12-17 CRITICAL 9.8 CVE-2021-41653EPSS 76% The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a cr… Tl Wr840n Firmware Mitigation only Fix from $2,3002021-11-13 MEDIUM 6.4 CVE-2021-29280 In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow Tl Wr840n Firmware No fix yet Fix from $1,6002021-08-19 HIGH 7.5 CVE-2021-28857 TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 username and password are sent via the cookie. Tl Wpa4220 Firmware No fix yet Fix from $1,9502021-06-15 MEDIUM 5.5 CVE-2021-28858 TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monitor traffic and capture the co… Tl Wpa4220 Firmware No fix yet Fix from $1,6002021-06-15 HIGH 8.8 CVE-2021-31659 TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information i… Tl Sg2005 Firmware Mitigation only Fix from $1,9502021-06-10 HIGH 8.1 CVE-2021-31658 TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface that provides the "device descri… Tl Sg2005 Firmware Mitigation only Fix from $1,9502021-06-10 MEDIUM 6.1 CVE-2020-17891 TP-Link Archer C1200 firmware version 1.13 Build 2018/01/24 rel.52299 EU has a XSS vulnerability allowing a remote attacker to execute arbitrary code. Archer C1200 Firmware No fix yet Fix from $1,6002021-05-14 HIGH 8.0 CVE-2021-27246EPSS 7% This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 AC1750 1.0.15 routers. … Ac1750 Firmware Mitigation only Fix from $1,9502021-04-14 HIGH 7.5 CVE-2021-26827 Buffer Overflow in TP-Link WR2041 v1 firmware for the TL-WR2041+ router allows remote attackers to cause a Denial-of-Service (DoS) by sending an HTTP… Tl Wr2041\+ Firmware No fix yet Fix from $1,9502021-04-14 HIGH 8.1 CVE-2021-27245 This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 prior to Archer C7(US)_V5_210125 and Archer A7(US)_V5_2002… Archer A7 Firmware Mitigation only Fix from $1,9502021-03-29 MEDIUM 6.1 CVE-2021-3275 Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers), Access Points, AD… Td W9977 Firmware No fix yet Fix from $1,6002021-03-26 HIGH 7.1 CVE-2021-27209 In the management interface on TP-Link Archer C5v 1.7_181221 devices, credentials are sent in a base64 format over cleartext HTTP. Archer C5v Firmware No fix yet Fix from $1,9502021-02-13 MEDIUM 6.5 CVE-2021-27210 TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,0#0,0,0,0,0,0]0,0 to the /cgi… Archer C5v Firmware No fix yet Fix from $1,6002021-02-13 CRITICAL 9.8 CVE-2020-36178EPSS 10% oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web in… Tl Wr840n Firmware No fix yet Fix from $2,3002021-01-06 MEDIUM 6.1 CVE-2020-5797 UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with physical access and network … Archer C9 Firmware No fix yet Fix from $1,6002020-11-21 CRITICAL 9.8 CVE-2020-28877 Buffer overflow in in the copy_msg_element function for the devDiscoverHandle server in the TP-Link WR and WDR series, including WDR7400, WDR7500, WD… Wdr7400 Firmware Mitigation only Fix from $2,3002020-11-20 HIGH 8.8 CVE-2020-24297 httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS commands by sending crafted POST… Tl Wpa4220 Firmware No fix yet Fix from $1,9502020-11-18 MEDIUM 6.5 CVE-2020-28005 httpd on TP-Link TL-WPA4220 devices (hardware versions 2 through 4) allows remote authenticated users to trigger a buffer overflow (causing a denial … Tl Wpa4220 Firmware No fix yet Fix from $1,6002020-11-18 MEDIUM 6.2 CVE-2020-5795 UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)_V5_200721 allows an authenticated admin user, with physical access and network access… Archer A7 Firmware No fix yet Fix from $1,6002020-11-06 HIGH 8.0 CVE-2020-10916 This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA855RE Firmware Ver: 855rev4-up-… Tl Wa855re Firmware Mitigation only Fix from $1,9502020-05-07 HIGH 8.8 CVE-2020-12109EPSS 74% Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3… Nc200 Firmware No fix yet Fix from $1,9502020-05-04 HIGH 8.8 CVE-2020-12111EPSS 8% Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304. Nc260 Firmware No fix yet Fix from $1,9502020-05-04 CRITICAL 9.8 CVE-2020-12110EPSS 13% Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC… Nc200 Firmware No fix yet Fix from $2,3002020-05-04