Vulnerability index

Browse CVEs

510 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tapo C260 Firmware HIGH 7.8
CVE-2026-0651

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET request…

Fix: 1.1.9+
Fix from $1,950 2026-02-10
Tapo H100 Firmware HIGH 8.8
CVE-2025-15557

An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to i…

Fix: 1.2.6 / 1.6.1+
Fix from $1,950 2026-02-05
Archer Mr200 Firmware MEDIUM 5.6
CVE-2025-15551

The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is getting executed by the JavaScri…

Fix: 0.9.1_Build251205 / 250630+
Fix from $1,600 2026-02-05
Archer Ax53 Firmware HIGH 8.1
CVE-2025-62501

SSH Hostkey misconfiguration vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows attackers to obtain device credentials through a sp…

Mitigation only
Fix from $1,950 2026-02-03
Archer Ax53 Firmware HIGH 8.0
CVE-2025-62673

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or p…

Mitigation only
Fix from $1,950 2026-02-03
Archer Ax53 Firmware HIGH 8.0
CVE-2025-58455

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…

Mitigation only
Fix from $1,950 2026-02-03
Archer Ax53 Firmware HIGH 8.0
CVE-2025-59482

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…

Mitigation only
Fix from $1,950 2026-02-03
Archer Ax53 Firmware HIGH 8.0
CVE-2025-59487

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…

Mitigation only
Fix from $1,950 2026-02-03
Archer Ax53 Firmware HIGH 8.0
CVE-2025-61944

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…

Mitigation only
Fix from $1,950 2026-02-03
Archer Ax53 Firmware HIGH 8.0
CVE-2025-61983

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…

Mitigation only
Fix from $1,950 2026-02-03
Archer Ax53 Firmware HIGH 8.0
CVE-2025-62404

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…

Mitigation only
Fix from $1,950 2026-02-03
Archer Ax53 Firmware HIGH 8.0
CVE-2025-62405

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…

Mitigation only
Fix from $1,950 2026-02-03
Archer Ax53 Firmware HIGH 8.0
CVE-2025-58077

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…

Mitigation only
Fix from $1,950 2026-02-03
Archer Be230 Firmware HIGH 8.0
CVE-2026-22223

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attacker execute arbitrary code. …

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 7.2
CVE-2026-22224

A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface on the TP-Link Archer BE230 …

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 7.2
CVE-2026-22225

A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the Archer BE230 v1.2  and Arche…

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 7.2
CVE-2026-22226

A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration module on TP-Link Archer BE230 v1…

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 7.2
CVE-2026-22227

A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restoration function of the TP-Link …

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 7.2
CVE-2026-22229

A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN client configuration file on the …

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 8.0
CVE-2026-22221

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attacker execute arbitrary code. …

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 8.0
CVE-2026-22222

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attacker to execute arbitrary code.…

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 8.0
CVE-2026-0630

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent authenticated attacker to e…

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Archer Be230 Firmware HIGH 8.0
CVE-2026-0631

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjacent authenticated attacker…

Fix: 1.2.4+
Fix from $1,950 2026-02-02
Vigi C385 Firmware HIGH 8.8
CVE-2026-1457EPSS 7%

An authenticated buffer handling flaw in TP-Link VIGI C385 V1 Web API lacking input sanitization, may allow memory corruption leading to remote code …

Fix: 3.1.1+
Fix from $1,950 2026-01-29
Vx800v Firmware MEDIUM 6.5
CVE-2025-15548

Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application layer encryption, allowing a…

Fix: 800.0.18+
Fix from $1,600 2026-01-29
Vx800v Firmware MEDIUM 6.3
CVE-2025-15541

Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files…

Fix: 800.0.11+
Fix from $1,600 2026-01-29
Vx800v Firmware MEDIUM 5.3
CVE-2025-15542

Improper handling of exceptional conditions in VX800v v1.0 in SIP processing allows an attacker to flood the device with crafted INVITE messages, blo…

Fix: 800.0.12+
Fix from $1,600 2026-01-29
Vx800v Firmware HIGH 8.8
CVE-2025-13399

A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force the weak AES key and decrypt…

Fix: 800.0.11+
Fix from $1,950 2026-01-29
Archer Re605x Firmware MEDIUM 6.8
CVE-2025-15545

The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, …

Fix: 1.2.10+
Fix from $1,600 2026-01-29
Tapo C220 Firmware HIGH 7.5
CVE-2026-0919

The HTTP parser of Tapo C210 v3, C220 v1 and C520WS v2 cameras improperly handles requests containing an excessively long URL path. An invalid‑URL er…

Fix: 1.2.3 / 1.4.2+
Fix from $1,950 2026-01-27