Vulnerability index

Browse CVEs

510 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tl Wr840n Firmware MEDIUM 6.4
CVE-2021-29280

In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow

No fix yet
Fix from $1,600 2021-08-19
Ue330 Firmware MEDIUM 5.9
CVE-2021-38543

TP-Link UE330 USB splitter devices through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, al…

Fix: after 2021-08-09
Fix from $1,600 2021-08-11
Tl Wpa4220 Firmware HIGH 7.5
CVE-2021-28857

TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 username and password are sent via the cookie.

No fix yet
Fix from $1,950 2021-06-15
Tl Wpa4220 Firmware MEDIUM 5.5
CVE-2021-28858

TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monitor traffic and capture the co…

No fix yet
Fix from $1,600 2021-06-15
Tl Sg2005 Firmware HIGH 8.8
CVE-2021-31659

TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information i…

Mitigation only
Fix from $1,950 2021-06-10
Tl Sg2005 Firmware HIGH 8.1
CVE-2021-31658

TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface that provides the "device descri…

Mitigation only
Fix from $1,950 2021-06-10
Archer C1200 Firmware MEDIUM 6.1
CVE-2020-17891

TP-Link Archer C1200 firmware version 1.13 Build 2018/01/24 rel.52299 EU has a XSS vulnerability allowing a remote attacker to execute arbitrary code.

No fix yet
Fix from $1,600 2021-05-14
Ac1750 Firmware HIGH 8.0
CVE-2021-27246EPSS 7%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 AC1750 1.0.15 routers. …

Mitigation only
Fix from $1,950 2021-04-14
Tl Wr2041\+ Firmware HIGH 7.5
CVE-2021-26827

Buffer Overflow in TP-Link WR2041 v1 firmware for the TL-WR2041+ router allows remote attackers to cause a Denial-of-Service (DoS) by sending an HTTP…

No fix yet
Fix from $1,950 2021-04-14
Tl Wr802n Firmware HIGH 8.1
CVE-2021-29302EPSS 6%

TP-Link TL-WR802N(US), Archer_C50v5_US v4_200 <= 2020.06 contains a buffer overflow vulnerability in the httpd process in the body message. The attac…

Fix: after 2020.06
Fix from $1,950 2021-04-12
Tl Xdr3230 Firmware HIGH 7.5
CVE-2021-3125

In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, TL-XDR5430 < 1.0.11, and possi…

Fix: 1.0.2 / 1.0.9+
Fix from $1,950 2021-04-12
Archer A7 Firmware HIGH 8.1
CVE-2021-27245

This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 prior to Archer C7(US)_V5_210125 and Archer A7(US)_V5_2002…

Mitigation only
Fix from $1,950 2021-03-29
Td W9977 Firmware MEDIUM 6.1
CVE-2021-3275

Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers), Access Points, AD…

No fix yet
Fix from $1,600 2021-03-26
Archer C5v Firmware HIGH 7.1
CVE-2021-27209

In the management interface on TP-Link Archer C5v 1.7_181221 devices, credentials are sent in a base64 format over cleartext HTTP.

No fix yet
Fix from $1,950 2021-02-13
Archer C5v Firmware MEDIUM 6.5
CVE-2021-27210

TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,0#0,0,0,0,0,0]0,0 to the /cgi…

No fix yet
Fix from $1,600 2021-02-13
Tl Wr841n Firmware HIGH 8.8
CVE-2020-35576EPSS 42%

A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users t…

Fix: 201216+
Fix from $1,950 2021-01-26
Tl Wr840n Firmware CRITICAL 9.8
CVE-2020-36178EPSS 10%

oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web in…

No fix yet
Fix from $2,300 2021-01-06
Wa901nd Firmware CRITICAL 9.8
CVE-2020-35575EPSS 8%

A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web pan…

Fix: 3.16.9+
Fix from $2,300 2020-12-26
Archer C9 Firmware MEDIUM 6.1
CVE-2020-5797

UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with physical access and network …

No fix yet
Fix from $1,600 2020-11-21
Wdr7400 Firmware CRITICAL 9.8
CVE-2020-28877

Buffer overflow in in the copy_msg_element function for the devDiscoverHandle server in the TP-Link WR and WDR series, including WDR7400, WDR7500, WD…

Mitigation only
Fix from $2,300 2020-11-20
Tl Wpa4220 Firmware HIGH 8.8
CVE-2020-24297

httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS commands by sending crafted POST…

No fix yet
Fix from $1,950 2020-11-18
Tl Wpa4220 Firmware MEDIUM 6.5
CVE-2020-28005

httpd on TP-Link TL-WPA4220 devices (hardware versions 2 through 4) allows remote authenticated users to trigger a buffer overflow (causing a denial …

No fix yet
Fix from $1,600 2020-11-18
Ac1750 Firmware CRITICAL 9.8
CVE-2020-28347EPSS 77%

tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this…

Fix: 201029+
Fix from $2,300 2020-11-08
Archer A7 Firmware MEDIUM 6.2
CVE-2020-5795

UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)_V5_200721 allows an authenticated admin user, with physical access and network access…

No fix yet
Fix from $1,600 2020-11-06
Tl Wa855re Firmware HIGH 8.8
CVE-2020-24363 KEVEPSS 21%

TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a fac…

Fix: 200731+
Fix from $1,950 2020-08-31
Tl Ps310u Firmware HIGH 8.8
CVE-2020-15054

TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate privileges because the administr…

Fix: 2.079.000.t0210+
Fix from $1,950 2020-08-07
Tl Ps310u Firmware HIGH 8.8
CVE-2020-15055

TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to bypass authentication via a web-administ…

Fix: 2.079.000.t0210+
Fix from $1,950 2020-08-07
Tl Ps310u Firmware MEDIUM 6.5
CVE-2020-15057

TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to denial-of-service the device via long in…

Fix: 2.079.000.t0210+
Fix from $1,600 2020-08-07
Nc200 Firmware HIGH 8.8
CVE-2020-13224

TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices…

Fix: after 2.1.10
Fix from $1,950 2020-06-17
Tl Wa855re Firmware HIGH 8.0
CVE-2020-10916

This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA855RE Firmware Ver: 855rev4-up-…

Mitigation only
Fix from $1,950 2020-05-07