Vulnerability index

Browse CVEs

510 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tapo C220 Firmware HIGH 7.5
CVE-2026-1315

By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying a…

Fix: 1.2.3 / 1.4.2+
Fix from $1,950 2026-01-27
Tapo C220 Firmware HIGH 7.5
CVE-2026-0918

The Tapo C100 v5, C220 v1 and C520WS v2 cameras’ HTTP service does not safely handle POST requests containing an excessively large Content-Length hea…

Fix: 1.2.3 / 1.4.2+
Fix from $1,950 2026-01-27
Omada Controller MEDIUM 5.3
CVE-2025-9522

Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which ma…

Fix: 6.0+
Fix from $1,600 2026-01-26
Omada Controller MEDIUM 6.8
CVE-2025-9520

An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijac…

Fix: 6.0+
Fix from $1,600 2026-01-26
Omada Controller MEDIUM 6.5
CVE-2025-9521

Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, an…

Fix: 6.0+
Fix from $1,600 2026-01-26
Archer Mr600 Firmware HIGH 8.8
CVE-2025-14756

Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to e…

Fix: 1.1.0+
Fix from $1,950 2026-01-26
Omada Controller MEDIUM 5.9
CVE-2025-9290

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of ra…

Fix: 1.1.3 / 1.2.2+
Fix from $1,600 2026-01-23
Archer Ax53 Firmware HIGH 8.8
CVE-2026-0834

Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to exec…

Mitigation only
Fix from $1,950 2026-01-21
Tl Wr841n Firmware HIGH 7.5
CVE-2025-9014

A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input vali…

Fix: 250908+
Fix from $1,950 2026-01-15
Archer Axe75 Firmware HIGH 7.3
CVE-2025-15035

Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary serv…

Fix: after 1.3.2
Fix from $1,950 2026-01-09
Archer Be400 Firmware MEDIUM 6.5
CVE-2025-14631

A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows  an adjacent attacker to cause a denial-of-service (DoS) …

Fix: after 1.1.0
Fix from $1,600 2026-01-07
Tl Wr820n Firmware MEDIUM 6.5
CVE-2025-14175

A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to inter…

Fix: 1.15.0+
Fix from $1,600 2025-12-29
Tapo C200 Firmware MEDIUM 6.5
CVE-2025-8065

A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags wit…

Mitigation only
Fix from $1,600 2025-12-20
Tapo C200 Firmware HIGH 8.1
CVE-2025-14300

The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authentication. An unauthenticated attacke…

Mitigation only
Fix from $1,950 2025-12-20
Tapo C200 Firmware MEDIUM 6.5
CVE-2025-14299

The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated atta…

Mitigation only
Fix from $1,600 2025-12-20
Tl Wa850re Firmware HIGH 8.0
CVE-2025-14737

Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue aff…

Fix: after 160922
Fix from $1,950 2025-12-18
Tl Wa850re Firmware HIGH 7.5
CVE-2025-14738

Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This iss…

Fix: after 160922
Fix from $1,950 2025-12-18
Er8411 Firmware CRITICAL 9.8
CVE-2025-6542

An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.

Fix: 1.1.0 / 1.2.1+
Fix from $2,300 2025-10-21
Fr307 M2 Firmware CRITICAL 9.8
CVE-2025-7851

An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.

Fix: 1.0.3 / 1.1.4+
Fix from $2,300 2025-10-21
Er8411 Firmware HIGH 7.2
CVE-2025-7850

A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.

Fix: 1.1.0 / 1.2.1+
Fix from $1,950 2025-10-21
Er706w Firmware HIGH 8.8
CVE-2025-6541

An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.

Fix: 1.0.3 / 1.1.4+
Fix from $1,950 2025-10-21
Tl Wr841n Firmware HIGH 7.2
CVE-2025-9377 KEVEPSS 12%

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) …

Fix: 241108+
Fix from $1,950 2025-08-29
Kp303 Firmware HIGH 8.8
CVE-2025-8627

The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off condition and potential information l…

Fix: 1.1.0+
Fix from $1,950 2025-08-25
Tl Wr841n Firmware HIGH 7.5
CVE-2025-53713

A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_APC.htm file due to missing input pa…

Fix: after 160325
Fix from $1,950 2025-07-29
Tl Wr841n Firmware HIGH 7.5
CVE-2025-53714

A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WzdWlanSiteSurveyRpm_AP.htm file due to missing inp…

Fix: after 160325
Fix from $1,950 2025-07-29
Tl Wr841n Firmware HIGH 7.5
CVE-2025-53715

A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/Wan6to4TunnelCfgRpm.htm file due to missing input p…

Fix: after 160325
Fix from $1,950 2025-07-29
Tl Wr841n Firmware HIGH 7.5
CVE-2025-53711

A vulnerability has been found in TP-Link TL-WR841N v11, TL-WR842ND v2 and TL-WR494N v3. The vulnerability exists in the /userRpm/WlanNetworkRpm.htm …

Fix: after 160325
Fix from $1,950 2025-07-29
Tl Wr841n Firmware HIGH 7.5
CVE-2025-53712

A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_AP.htm file due to missing input par…

Fix: after 160325
Fix from $1,950 2025-07-29
Tl Wr940n Firmware HIGH 8.2
CVE-2025-6151

A vulnerability has been found in TP-Link TL-WR940N V4 and TL-WR841N V11. Affected by this issue is some unknown functionality of the file /userRpm…

No fix yet
Fix from $1,950 2025-06-17
Tl Ipc544ep W4 Firmware HIGH 8.8
CVE-2025-5875

A vulnerability classified as critical has been found in TP-LINK Technologies TL-IPC544EP-W4 1.0.9 Build 240428 Rel 69493n. Affected is the function …

No fix yet
Fix from $1,950 2025-06-09