Vulnerability index

Browse CVEs

510 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Archer C3200 V1 Firmware HIGH 8.8
CVE-2019-13266

TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are establish…

No fix yet
Fix from $1,950 2019-08-27
Archer C3200 V1 Firmware HIGH 8.8
CVE-2019-13267

TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are establish…

No fix yet
Fix from $1,950 2019-08-27
Archer C3200 V1 Firmware HIGH 8.8
CVE-2019-13268

TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are establish…

No fix yet
Fix from $1,950 2019-08-27
Tl Wr840n Firmware HIGH 8.8
CVE-2019-15060

The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payl…

Fix: after 0.9.1_3.16
Fix from $1,950 2019-08-22
M7350 Firmware CRITICAL 9.8
CVE-2019-12103

The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by a pre-authentication command injection vulne…

Fix: 190531+
Fix from $2,300 2019-08-14
M7350 Firmware HIGH 8.8
CVE-2019-12104

The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-authentication command injectio…

Fix: 190531+
Fix from $1,950 2019-08-14
Archer C1200 Firmware CRITICAL 9.8
CVE-2019-13614

CMD_SET_CONFIG_COUNTRY in the TP-Link Device Debug protocol in TP-Link Archer C1200 1.0.0 Build 20180502 rel.45702 and earlier is prone to a stack-ba…

No fix yet
Fix from $2,300 2019-07-17
Archer C1200 Firmware CRITICAL 9.8
CVE-2019-13613

CMD_FTEST_CONFIG in the TP-Link Device Debug protocol in TP-Link Wireless Router Archer Router version 1.0.0 Build 20180502 rel.45702 (EU) and earlie…

No fix yet
Fix from $2,300 2019-07-17
Tl Wr1043nd Firmware HIGH 7.2
CVE-2018-16119EPSS 34%

Stack-based buffer overflow in the httpd server of TP-Link WR1043nd (Firmware Version 3) allows remote attackers to execute arbitrary code via a mali…

No fix yet
Fix from $1,950 2019-06-20
Tl Wr1043nd Firmware CRITICAL 9.8
CVE-2019-6971EPSS 14%

An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packet to the router management we…

No fix yet
Fix from $2,300 2019-06-19
Tl Wr1043nd Firmware HIGH 7.5
CVE-2019-6972

An issue was discovered on TP-Link TL-WR1043ND V2 devices. The credentials can be easily decoded and cracked by brute-force, WordList, or Rainbow Tab…

No fix yet
Fix from $1,950 2019-06-19
Tl Wr940n Firmware HIGH 8.8
CVE-2019-6989EPSS 12%

TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispose function. By sending specia…

No fix yet
Fix from $1,950 2019-06-06
Archer Cr700 Firmware MEDIUM 6.1
CVE-2016-10719

TP-Link Archer CR-700 1.0.6 devices have an XSS vulnerability that can be introduced into the admin account through a DHCP request, allowing the atta…

No fix yet
Fix from $1,600 2019-05-15
Tl Wr840n Firmware HIGH 7.5
CVE-2018-15840

TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets, as demonstrated by an "nmap…

No fix yet
Fix from $1,950 2019-03-29
Tl Wdr5620 Firmware HIGH 8.8
CVE-2019-6487EPSS 9%

TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execu…

Fix: after 3.0
Fix from $1,950 2019-01-18
Td W8961nd Firmware MEDIUM 5.4
CVE-2018-20372

TP-Link TD-W8961ND devices allow XSS via the hostname of a DHCP client.

No fix yet
Fix from $1,600 2018-12-23
Tl R600vpn Firmware HIGH 7.2
CVE-2018-3951

An exploitable remote code execution vulnerability exists in the HTTP header-parsing function of the TP-Link TL-R600VPN HTTP Server. A specially craf…

No fix yet
Fix from $1,950 2018-12-01
Tl R600vpn Firmware HIGH 8.8
CVE-2018-3950

An exploitable remote code execution vulnerability exists in the ping and tracert functionality of the TP-Link TL-R600VPN HWv3 FRNv1.3.0 and HWv2 FRN…

No fix yet
Fix from $1,950 2018-12-01
Tl R600vpn Firmware HIGH 7.5
CVE-2018-3949EPSS 53%

An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN. A specially crafted URL can ca…

No fix yet
Fix from $1,950 2018-12-01
Tl R600vpn Firmware HIGH 7.5
CVE-2018-3948EPSS 23%

An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP server. A specially crafted URL…

No fix yet
Fix from $1,950 2018-11-30
Archer C5 Firmware HIGH 7.2
CVE-2018-19537EPSS 6%

TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuratio…

Fix: after 2_160201_us
Fix from $1,950 2018-11-26
Tl Wr886n Firmware CRITICAL 9.8
CVE-2018-19528

TP-Link TL-WR886N 7.0 1.1.0 devices allow remote attackers to cause a denial of service (Tlb Load Exception) via crafted DNS packets to port 53/udp.

No fix yet
Fix from $2,300 2018-11-26
Tl Sc3130 Firmware HIGH 7.5
CVE-2018-18428EPSS 11%

TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI.

No fix yet
Fix from $1,950 2018-10-19
Tl Wrn841n Firmware HIGH 8.8
CVE-2018-15702

The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to CSRF due to insufficient validation of the referer field.

Mitigation only
Fix from $1,950 2018-10-01
Tl Wrn841n Firmware MEDIUM 6.5
CVE-2018-15700

The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated LAN user sends a crafted HTTP…

Mitigation only
Fix from $1,600 2018-10-01
Tl Wrn841n Firmware MEDIUM 6.5
CVE-2018-15701

The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated LAN user sends a crafted HTTP…

Mitigation only
Fix from $1,600 2018-10-01
Eap Controller CRITICAL 9.8
CVE-2018-5393EPSS 13%

The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation …

Fix: after 2.5.3
Fix from $2,300 2018-09-28
Tl Wr886n Firmware MEDIUM 6.5
CVE-2018-17010

An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inet…

No fix yet
Fix from $1,600 2018-09-13
Tl Wr886n Firmware MEDIUM 6.5
CVE-2018-17011

An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inet…

No fix yet
Fix from $1,600 2018-09-13
Tl Wr886n Firmware MEDIUM 6.5
CVE-2018-17012

An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inet…

No fix yet
Fix from $1,600 2018-09-13