Vulnerability index

Browse CVEs

510 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.0 CVE-2026-30818 An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrar… Archer Ax53 Firmware 1.7.1+ Fix from $1,9502026-04-08 MEDIUM 5.7 CVE-2026-30816 An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbit… Archer Ax53 Firmware after 1.7.1 Fix from $1,6002026-04-08 MEDIUM 5.7 CVE-2026-30817 An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrar… Archer Ax53 Firmware 1.7.1+ Fix from $1,6002026-04-08 MEDIUM 6.5 CVE-2026-34122 A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling component due to insufficient … Tapo C520ws Firmware 1.2.4+ Fix from $1,6002026-04-02 MEDIUM 6.5 CVE-2026-34124 A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The implementation enforces … Tapo C520ws Firmware 1.2.4+ Fix from $1,6002026-04-02 HIGH 8.8 CVE-2026-34121 An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to in… Tapo C520ws Firmware 1.2.4+ Fix from $1,9502026-04-02 MEDIUM 6.5 CVE-2026-34118 A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 in the HTTP POST body parsing logic due to missing validation o… Tapo C520ws Firmware 1.2.4+ Fix from $1,6002026-04-02 MEDIUM 6.5 CVE-2026-34119 A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when appending segmented request b… Tapo C520ws Firmware 1.2.4+ Fix from $1,6002026-04-02 MEDIUM 6.5 CVE-2026-34120 A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing of local video stream content d… Tapo C520ws Firmware 1.2.4+ Fix from $1,6002026-04-02 MEDIUM 6.8 CVE-2026-4346 The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of the device’s flash memory wh… Tl Wr850n Firmware 0.9.1_Build251205+ Fix from $1,6002026-03-26 HIGH 7.5 CVE-2026-3622 The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-bounds read, potentially causing … Tl Wr841n Firmware 0.9.1_4.19+ Fix from $1,9502026-03-26 HIGH 7.5 CVE-2025-15606 A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitization, allows crafted request… Td W8961nd Firmware 250925+ Fix from $1,9502026-03-23 HIGH 7.3 CVE-2025-15605 A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption… Archer Nx600 Firmware 1.3.0 / 1.4.0+ Fix from $1,9502026-03-23 HIGH 7.2 CVE-2025-15518 Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be e… Archer Nx600 Firmware 1.3.0 / 1.4.0+ Fix from $1,9502026-03-23 HIGH 7.2 CVE-2025-15519 Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be e… Archer Nx600 Firmware 1.3.0 / 1.4.0+ Fix from $1,9502026-03-23 HIGH 8.1 CVE-2025-15517 A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated acc… Archer Nx600 Firmware 1.3.0 / 1.4.0+ Fix from $1,9502026-03-23 CRITICAL 9.8 CVE-2025-15608 This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalid… Archer Ax53 Firmware Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2025-15607 A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbit… Archer Ax53 Firmware Mitigation only Fix from $2,3002026-03-20 MEDIUM 6.8 CVE-2026-3227 A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special e… Tl Wr802n Firmware 260303 / 260304+ Fix from $1,6002026-03-16 CRITICAL 9.8 CVE-2026-1668 The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when … Omada Sg2005p Pd Firmware 1.0.19 / 1.20.17+ Fix from $2,3002026-03-13 HIGH 8.8 CVE-2026-3841 A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by … Tl Mr6400 Firmware 1.9.0+ Fix from $1,9502026-03-12 HIGH 8.0 CVE-2025-15568 A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network… Archer Axe75 Firmware 1.3.2+ Fix from $1,9502026-03-09 MEDIUM 6.5 CVE-2025-7375 A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can send crafted requests to cau… Omada Eap610 Firmware 1.6.0+ Fix from $1,6002026-03-05 HIGH 8.0 CVE-2026-0655 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (web modules) allows authentic… Deco Be25 Firmware after 1.1.1 Fix from $1,9502026-03-02 HIGH 8.0 CVE-2026-0654 Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. … Deco Be25 Firmware after 1.1.1 Fix from $1,9502026-03-02 HIGH 8.1 CVE-2025-9293 A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS c… Aginet 1.1.21 / 1.1.28+ Fix from $1,9502026-02-13 HIGH 7.5 CVE-2025-9292 A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. … Aginet 1.1.21 / 1.1.28+ Fix from $1,9502026-02-13 MEDIUM 6.1 CVE-2026-1571 User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbitrary JavaScript execution via… Archer C60 Firmware 260206+ Fix from $1,6002026-02-11 HIGH 8.8 CVE-2026-0652EPSS 22% On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchron… Tapo C260 Firmware 1.1.9+ Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2026-0653 On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchr… Tapo C260 Firmware 1.1.9+ Fix from $1,6002026-02-10