Vulnerability index

Browse CVEs

510 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nc200 Firmware HIGH 8.8
CVE-2020-12109EPSS 74%

Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3…

No fix yet
Fix from $1,950 2020-05-04
Nc260 Firmware HIGH 8.8
CVE-2020-12111EPSS 8%

Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.

No fix yet
Fix from $1,950 2020-05-04
Nc200 Firmware CRITICAL 9.8
CVE-2020-12110EPSS 13%

Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC…

No fix yet
Fix from $2,300 2020-05-04
Omada Controller MEDIUM 5.5
CVE-2020-12475

TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.portal.PortalController.getAdv…

No fix yet
Fix from $1,600 2020-05-04
Tl Wr841n Firmware HIGH 7.2
CVE-2020-8423EPSS 9%

A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute a…

No fix yet
Fix from $1,950 2020-04-02
Nc450 Firmware HIGH 7.5
CVE-2020-10231

TP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 through 1.3.0_Build_171205, NC250…

Patch available
Fix from $1,950 2020-04-01
Nc450 Firmware MEDIUM 5.3
CVE-2020-11445

TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive information via vectors involving a Wi-…

Fix: after 2020-02-09
Fix from $1,600 2020-04-01
Ac1750 Firmware CRITICAL 9.8
CVE-2020-10885EPSS 7%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 route…

Mitigation only
Fix from $2,300 2020-03-25
Ac1750 Firmware CRITICAL 9.8
CVE-2020-10886EPSS 6%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 route…

Mitigation only
Fix from $2,300 2020-03-25
Ac1750 Firmware CRITICAL 9.8
CVE-2020-10887

This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not…

Mitigation only
Fix from $2,300 2020-03-25
Ac1750 Firmware CRITICAL 9.8
CVE-2020-10888

This vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 router…

Mitigation only
Fix from $2,300 2020-03-25
Ac1750 Firmware HIGH 8.8
CVE-2020-10884EPSS 26%

This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC175…

No fix yet
Fix from $1,950 2020-03-25
Ac1750 Firmware HIGH 7.8
CVE-2020-10883EPSS 6%

This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. …

No fix yet
Fix from $1,950 2020-03-25
Ac1750 Firmware CRITICAL 9.8
CVE-2020-10881EPSS 11%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 route…

Mitigation only
Fix from $2,300 2020-03-25
Ac1750 Firmware HIGH 8.8
CVE-2020-10882EPSS 41%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC…

No fix yet
Fix from $1,950 2020-03-25
Archer C50 HIGH 7.5
CVE-2020-9375EPSS 27%

TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containin…

No fix yet
Fix from $1,950 2020-03-25
Tl Wr849n Firmware CRITICAL 9.8
CVE-2020-9374EPSS 42%

On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends spe…

No fix yet
Fix from $2,300 2020-02-24
Tp Sg105e Firmware HIGH 7.5
CVE-2019-16893EPSS 38%

The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the device via a reboot.cgi requ…

Patch available
Fix from $1,950 2020-02-03
Tl Wr1043nd Firmware HIGH 7.5
CVE-2013-2646

TP-LINK TL-WR1043ND V1_120405 devices contain an unspecified denial of service vulnerability.

No fix yet
Fix from $1,950 2020-02-03
Tl Sc 3130g Firmware CRITICAL 9.8
CVE-2013-2573EPSS 42%

A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G,…

Fix: after 1.6.18p12
Fix from $2,300 2020-01-29
Tl Sc 3130 Firmware HIGH 7.5
CVE-2013-2572EPSS 16%

A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded cred…

Fix: after 1.6.18p12
Fix from $1,950 2020-01-29
Tl Wr849n Firmware MEDIUM 6.1
CVE-2019-19143

TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI.

No fix yet
Fix from $1,600 2020-01-27
Tl Wr841n Firmware HIGH 8.8
CVE-2019-17147EPSS 14%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication is not re…

Mitigation only
Fix from $1,950 2020-01-07
Tl Wdr4300 Firmware CRITICAL 9.8
CVE-2013-4654

Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND..

No fix yet
Fix from $2,300 2019-11-13
Tl Wdr4300 Firmware HIGH 8.8
CVE-2013-4848

TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.

No fix yet
Fix from $1,950 2019-10-25
M7350 Firmware CRITICAL 9.8
CVE-2019-13649

TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow externalPort OS Command Injection (issue 1 of 5).

Fix: after 1.0.16
Fix from $2,300 2019-10-24
M7350 Firmware CRITICAL 9.8
CVE-2019-13650

TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow internalPort OS Command Injection (issue 2 of 5).

Fix: after 1.0.16
Fix from $2,300 2019-10-24
M7350 Firmware CRITICAL 9.8
CVE-2019-13651

TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow portMappingProtocol OS Command Injection (issue 3 of 5).

Fix: after 1.0.16
Fix from $2,300 2019-10-24
M7350 Firmware CRITICAL 9.8
CVE-2019-13652

TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow serviceName OS Command Injection (issue 4 of 5).

Fix: after 1.0.16
Fix from $2,300 2019-10-24
M7350 Firmware CRITICAL 9.8
CVE-2019-13653

TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow triggerPort OS Command Injection (issue 5 of 5).

Fix: after 1.0.16
Fix from $2,300 2019-10-24