Vulnerability index

Browse CVEs

510 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-1315 By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying a… Tapo C220 Firmware 1.2.3 / 1.4.2+ Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-0918 The Tapo C100 v5, C220 v1 and C520WS v2 cameras’ HTTP service does not safely handle POST requests containing an excessively large Content-Length hea… Tapo C220 Firmware 1.2.3 / 1.4.2+ Fix from $1,9502026-01-27 MEDIUM 5.3 CVE-2025-9522 Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which ma… Omada Controller 6.0+ Fix from $1,6002026-01-26 MEDIUM 6.8 CVE-2025-9520 An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijac… Omada Controller 6.0+ Fix from $1,6002026-01-26 MEDIUM 6.5 CVE-2025-9521 Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, an… Omada Controller 6.0+ Fix from $1,6002026-01-26 HIGH 8.8 CVE-2025-14756 Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to e… Archer Mr600 Firmware 1.1.0+ Fix from $1,9502026-01-26 MEDIUM 5.9 CVE-2025-9290 An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of ra… Omada Controller 1.1.3 / 1.2.2+ Fix from $1,6002026-01-23 HIGH 8.8 CVE-2026-0834 Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to exec… Archer Ax53 Firmware Mitigation only Fix from $1,9502026-01-21 HIGH 7.5 CVE-2025-9014 A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input vali… Tl Wr841n Firmware 250908+ Fix from $1,9502026-01-15 HIGH 7.3 CVE-2025-15035 Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary serv… Archer Axe75 Firmware after 1.3.2 Fix from $1,9502026-01-09 MEDIUM 6.5 CVE-2025-14631 A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows  an adjacent attacker to cause a denial-of-service (DoS) … Archer Be400 Firmware after 1.1.0 Fix from $1,6002026-01-07 MEDIUM 6.5 CVE-2025-14175 A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to inter… Tl Wr820n Firmware 1.15.0+ Fix from $1,6002025-12-29 MEDIUM 6.5 CVE-2025-8065 A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags wit… Tapo C200 Firmware Mitigation only Fix from $1,6002025-12-20 HIGH 8.1 CVE-2025-14300 The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authentication. An unauthenticated attacke… Tapo C200 Firmware Mitigation only Fix from $1,9502025-12-20 MEDIUM 6.5 CVE-2025-14299 The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated atta… Tapo C200 Firmware Mitigation only Fix from $1,6002025-12-20 HIGH 8.0 CVE-2025-14737 Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue aff… Tl Wa850re Firmware after 160922 Fix from $1,9502025-12-18 HIGH 7.5 CVE-2025-14738 Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This iss… Tl Wa850re Firmware after 160922 Fix from $1,9502025-12-18 CRITICAL 9.8 CVE-2025-6542 An arbitrary OS command may be executed on the product by a remote unauthenticated attacker. Er8411 Firmware 1.1.0 / 1.2.1+ Fix from $2,3002025-10-21 CRITICAL 9.8 CVE-2025-7851 An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. Fr307 M2 Firmware 1.0.3 / 1.1.4+ Fix from $2,3002025-10-21 HIGH 7.2 CVE-2025-7850 A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. Er8411 Firmware 1.1.0 / 1.2.1+ Fix from $1,9502025-10-21 HIGH 8.8 CVE-2025-6541 An arbitrary OS command may be executed on the product by the user who can log in to the web management interface. Er706w Firmware 1.0.3 / 1.1.4+ Fix from $1,9502025-10-21 HIGH 7.2 CVE-2025-9377 KEVEPSS 12% The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) … Tl Wr841n Firmware 241108+ Fix from $1,9502025-08-29 HIGH 8.8 CVE-2025-8627 The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off condition and potential information l… Kp303 Firmware 1.1.0+ Fix from $1,9502025-08-25 HIGH 7.5 CVE-2025-53713 A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_APC.htm file due to missing input pa… Tl Wr841n Firmware after 160325 Fix from $1,9502025-07-29 HIGH 7.5 CVE-2025-53714 A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WzdWlanSiteSurveyRpm_AP.htm file due to missing inp… Tl Wr841n Firmware after 160325 Fix from $1,9502025-07-29 HIGH 7.5 CVE-2025-53715 A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/Wan6to4TunnelCfgRpm.htm file due to missing input p… Tl Wr841n Firmware after 160325 Fix from $1,9502025-07-29 HIGH 7.5 CVE-2025-53711 A vulnerability has been found in TP-Link TL-WR841N v11, TL-WR842ND v2 and TL-WR494N v3. The vulnerability exists in the /userRpm/WlanNetworkRpm.htm … Tl Wr841n Firmware after 160325 Fix from $1,9502025-07-29 HIGH 7.5 CVE-2025-53712 A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_AP.htm file due to missing input par… Tl Wr841n Firmware after 160325 Fix from $1,9502025-07-29 HIGH 8.2 CVE-2025-6151 A vulnerability has been found in TP-Link TL-WR940N V4 and TL-WR841N V11. Affected by this issue is some unknown functionality of the file /userRpm… Tl Wr940n Firmware No fix yet Fix from $1,9502025-06-17 HIGH 8.8 CVE-2025-5875 A vulnerability classified as critical has been found in TP-LINK Technologies TL-IPC544EP-W4 1.0.9 Build 240428 Rel 69493n. Affected is the function … Tl Ipc544ep W4 Firmware No fix yet Fix from $1,9502025-06-09