Vulnerability index

Browse CVEs

510 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tl Wvr300 Firmware HIGH 8.8
CVE-2017-16958

TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bind…

No fix yet
Fix from $1,950 2017-11-27
Tl Er5510g HIGH 8.8
CVE-2017-16960

TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bind…

Mitigation only
Fix from $1,950 2017-11-27
Tl Wvr300 Firmware MEDIUM 6.5
CVE-2017-16959

The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of …

No fix yet
Fix from $1,600 2017-11-27
Wr940n Firmware HIGH 8.8
CVE-2017-13772EPSS 53%

Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary co…

No fix yet
Fix from $1,950 2017-10-23
Tl Mr3220 Firmware MEDIUM 6.1
CVE-2017-15291

Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject a…

No fix yet
Fix from $1,600 2017-10-20
Archer C9 \(2.0\) Firmware CRITICAL 9.8
CVE-2017-11519

passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random number g…

No fix yet
Fix from $2,300 2017-07-21
Nc250 Firmware MEDIUM 6.5
CVE-2017-10796

On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:…

Fix: after 1.2.1
Fix from $1,600 2017-07-02
Wr841n V8 Firmware CRITICAL 9.8
CVE-2017-9466

The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption. T…

No fix yet
Fix from $2,300 2017-06-26
C2 Firmware CRITICAL 9.9
CVE-2017-8220EPSS 37%

TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by plac…

Fix: after 0.9.1_4.2_v0032.0_build_160706
Fix from $2,300 2017-04-25
C2 Firmware CRITICAL 9.8
CVE-2017-8218

vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n has a backdoor admin account with the 1234 password,…

Fix: after 0.9.1_4.2_v0032.0_build_160706
Fix from $2,300 2017-04-25
C2 Firmware MEDIUM 6.5
CVE-2017-8219

TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow DoSing the HTTP server via a crafted Cookie header to th…

Fix: after 0.9.1_4.2_v0032.0_build_160706
Fix from $1,600 2017-04-25
C2 Firmware MEDIUM 5.3
CVE-2017-8217

TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n have too permissive iptables rules, e.g., SNMP is not blocked …

Fix: after 0.9.1_4.2_v0032.0_build_160706
Fix from $1,600 2017-04-25
Tl Sg108e Firmware CRITICAL 9.8
CVE-2017-8074

On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadecimal. Thi…

No fix yet
Fix from $2,300 2017-04-23
Tl Sg108e Firmware CRITICAL 9.8
CVE-2017-8075

On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext. This affect…

No fix yet
Fix from $2,300 2017-04-23
Tl Sg108e Firmware CRITICAL 9.8
CVE-2017-8076

On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is deprecated. This affects the 1.1.2 Build 20141017 Rel.…

No fix yet
Fix from $2,300 2017-04-23
Tl Sg108e Firmware HIGH 7.5
CVE-2017-8077

On the TP-Link TL-SG108E 1.0, there is a hard-coded ciphering key (a long string beginning with Ei2HNryt). This affects the 1.1.2 Build 20141017 Rel.…

No fix yet
Fix from $1,950 2017-04-23
Tl Sg108e Firmware MEDIUM 5.3
CVE-2017-8078

On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd). This af…

No fix yet
Fix from $1,600 2017-04-23
Tp Link HIGH 7.5
CVE-2016-1000009

TP-LINK lost control of two domains, www.tplinklogin.net and tplinkextender.net. Please note that these domains are physically printed on many of the…

Mitigation only
Fix from $1,950 2016-10-06
Tl Wr741nd Firmware HIGH 7.5
CVE-2015-3035 KEVEPSS 84%

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with fir…

Fix: 150302 / 150304+
Fix from $1,950 2015-04-22
Tl Wr840n Firmware MEDIUM 6.8
CVE-2014-9510

Cross-site request forgery (CSRF) vulnerability in the administration console in TP-Link TL-WR840N (V1) router with firmware before 3.13.27 build 141…

Patch available
Fix from $1,600 2015-01-09
Tl Wr740n Firmware MEDIUM 5.0
CVE-2014-9350EPSS 7%

TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a denial of serv…

No fix yet
Fix from $1,600 2014-12-08
Firmware HIGH 9.3
CVE-2013-2645

Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_120405 allow remote attackers t…

Mitigation only
Fix from $1,950 2014-10-06
Tl Wdr4300 Firmware MEDIUM 5.0
CVE-2014-4728

The web server in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to cause a deni…

Fix: after 130617
Fix from $1,600 2014-09-30
Tl Sc3130 HIGH 10.0
CVE-2013-2579

TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an empty pass…

Fix: after 1.6.18p12_sign5
Fix from $1,950 2013-10-11
Tl Sc3130 HIGH 7.8
CVE-2013-2581

cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P…

Fix: after 1.6.18p12_sign5
Fix from $1,950 2013-10-11
Tl Sc3130 HIGH 7.1
CVE-2013-2580

Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other m…

Fix: after 1.6.18p12_sign5
Fix from $1,950 2013-10-11
Tl Sc3130 HIGH 10.0
CVE-2013-2578EPSS 74%

cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P…

Fix: after 1.6.18p12_sign5
Fix from $1,950 2013-10-11
Tl Sc3130 HIGH 7.1
CVE-2013-3688

The TP-Link IP Cameras TL-SC3171, TL-SC3130, TL-SC3130G, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, does not prop…

Fix: after 1.6.18p12_sign5
Fix from $1,950 2013-10-01
Tl Wr841n HIGH 7.8
CVE-2012-5687EPSS 69%

Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n an…

Fix: after 3.13.9
Fix from $1,950 2012-11-01
8840t HIGH 7.5
CVE-2012-2440

The default configuration of the TP-Link 8840T router enables web-based administration on the WAN interface, which allows remote attackers to establi…

Mitigation only
Fix from $1,950 2012-04-28