Vulnerability index

Browse CVEs

510 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Archer Ax53 Firmware HIGH 8.0
CVE-2026-30818

An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrar…

Fix: 1.7.1+
Fix from $1,950 2026-04-08
Archer Ax53 Firmware MEDIUM 5.7
CVE-2026-30816

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbit…

Fix: after 1.7.1
Fix from $1,600 2026-04-08
Archer Ax53 Firmware MEDIUM 5.7
CVE-2026-30817

An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrar…

Fix: 1.7.1+
Fix from $1,600 2026-04-08
Tapo C520ws Firmware MEDIUM 6.5
CVE-2026-34122

A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling component due to insufficient …

Fix: 1.2.4+
Fix from $1,600 2026-04-02
Tapo C520ws Firmware MEDIUM 6.5
CVE-2026-34124

A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The implementation enforces …

Fix: 1.2.4+
Fix from $1,600 2026-04-02
Tapo C520ws Firmware HIGH 8.8
CVE-2026-34121

An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to in…

Fix: 1.2.4+
Fix from $1,950 2026-04-02
Tapo C520ws Firmware MEDIUM 6.5
CVE-2026-34118

A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 in the HTTP POST body parsing logic due to missing validation o…

Fix: 1.2.4+
Fix from $1,600 2026-04-02
Tapo C520ws Firmware MEDIUM 6.5
CVE-2026-34119

A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when appending segmented request b…

Fix: 1.2.4+
Fix from $1,600 2026-04-02
Tapo C520ws Firmware MEDIUM 6.5
CVE-2026-34120

A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing of local video stream content d…

Fix: 1.2.4+
Fix from $1,600 2026-04-02
Tl Wr850n Firmware MEDIUM 6.8
CVE-2026-4346

The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of the device’s flash memory wh…

Fix: 0.9.1_Build251205+
Fix from $1,600 2026-03-26
Tl Wr841n Firmware HIGH 7.5
CVE-2026-3622

The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-bounds read, potentially causing …

Fix: 0.9.1_4.19+
Fix from $1,950 2026-03-26
Td W8961nd Firmware HIGH 7.5
CVE-2025-15606

A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitization, allows crafted request…

Fix: 250925+
Fix from $1,950 2026-03-23
Archer Nx600 Firmware HIGH 7.3
CVE-2025-15605

A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption…

Fix: 1.3.0 / 1.4.0+
Fix from $1,950 2026-03-23
Archer Nx600 Firmware HIGH 7.2
CVE-2025-15518

Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be e…

Fix: 1.3.0 / 1.4.0+
Fix from $1,950 2026-03-23
Archer Nx600 Firmware HIGH 7.2
CVE-2025-15519

Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be e…

Fix: 1.3.0 / 1.4.0+
Fix from $1,950 2026-03-23
Archer Nx600 Firmware HIGH 8.1
CVE-2025-15517

A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated acc…

Fix: 1.3.0 / 1.4.0+
Fix from $1,950 2026-03-23
Archer Ax53 Firmware CRITICAL 9.8
CVE-2025-15608

This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalid…

Mitigation only
Fix from $2,300 2026-03-20
Archer Ax53 Firmware CRITICAL 9.8
CVE-2025-15607

A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbit…

Mitigation only
Fix from $2,300 2026-03-20
Tl Wr802n Firmware MEDIUM 6.8
CVE-2026-3227

A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special e…

Fix: 260303 / 260304+
Fix from $1,600 2026-03-16
Omada Sg2005p Pd Firmware CRITICAL 9.8
CVE-2026-1668

The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when …

Fix: 1.0.19 / 1.20.17+
Fix from $2,300 2026-03-13
Tl Mr6400 Firmware HIGH 8.8
CVE-2026-3841

A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by …

Fix: 1.9.0+
Fix from $1,950 2026-03-12
Archer Axe75 Firmware HIGH 8.0
CVE-2025-15568

A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network…

Fix: 1.3.2+
Fix from $1,950 2026-03-09
Omada Eap610 Firmware MEDIUM 6.5
CVE-2025-7375

A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can send crafted requests to cau…

Fix: 1.6.0+
Fix from $1,600 2026-03-05
Deco Be25 Firmware HIGH 8.0
CVE-2026-0655

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (web modules) allows authentic…

Fix: after 1.1.1
Fix from $1,950 2026-03-02
Deco Be25 Firmware HIGH 8.0
CVE-2026-0654

Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. …

Fix: after 1.1.1
Fix from $1,950 2026-03-02
Aginet HIGH 8.1
CVE-2025-9293

A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS c…

Fix: 1.1.21 / 1.1.28+
Fix from $1,950 2026-02-13
Aginet HIGH 7.5
CVE-2025-9292

A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. …

Fix: 1.1.21 / 1.1.28+
Fix from $1,950 2026-02-13
Archer C60 Firmware MEDIUM 6.1
CVE-2026-1571

User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbitrary JavaScript execution via…

Fix: 260206+
Fix from $1,600 2026-02-11
Tapo C260 Firmware HIGH 8.8
CVE-2026-0652EPSS 22%

On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchron…

Fix: 1.1.9+
Fix from $1,950 2026-02-10
Tapo C260 Firmware MEDIUM 6.5
CVE-2026-0653

On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchr…

Fix: 1.1.9+
Fix from $1,600 2026-02-10