Filtered by vendor Tp-link
Subscribe
Total
513 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-15608 | 1 Tp-link | 2 Archer Ax53, Archer Ax53 Firmware | 2026-08-12 | N/A | 9.8 CRITICAL |
| This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, may enable remote code execution through complex heap-spray techniques. Successful exploitation may result in repeated service unavailability and, in certain scenarios, allow an attacker to gain control of the device. | |||||
| CVE-2026-15314 | 1 Tp-link | 2 Tapo P110, Tapo P110 Firmware | 2026-08-07 | N/A | 7.5 HIGH |
| Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash. Successful exploitation may cause the web service process to stop responding or restart, resulting in a denial-of-service condition. | |||||
| CVE-2026-9044 | 1 Tp-link | 2 Archer Axe75, Archer Axe75 Firmware | 2026-08-07 | N/A | 8.0 HIGH |
| An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters. Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability. | |||||
| CVE-2025-9291 | 1 Tp-link | 218 Omada Ds1008x, Omada Ds1008x Firmware, Omada Ds1016g and 215 more | 2026-08-07 | N/A | 6.5 MEDIUM |
| A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers. | |||||
| CVE-2025-15544 | 1 Tp-link | 225 Omada, Omada Ds1008x, Omada Ds1008x Firmware and 222 more | 2026-08-07 | N/A | 5.9 MEDIUM |
| A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments. | |||||
| CVE-2025-15627 | 1 Tp-link | 224 Omada Ds1008x, Omada Ds1008x Firmware, Omada Ds1016g and 221 more | 2026-08-07 | N/A | 7.5 HIGH |
| A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications. | |||||
| CVE-2025-15628 | 1 Tp-link | 224 Omada Ds1008x, Omada Ds1008x Firmware, Omada Ds1016g and 221 more | 2026-08-07 | N/A | 7.5 HIGH |
| Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications. | |||||
| CVE-2025-15629 | 1 Tp-link | 224 Omada Ds1008x, Omada Ds1008x Firmware, Omada Ds1016g and 221 more | 2026-08-07 | N/A | 7.5 HIGH |
| A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be able to recover session encryption keys and decrypt affected communications. | |||||
| CVE-2025-15630 | 1 Tp-link | 224 Omada Ds1008x, Omada Ds1008x Firmware, Omada Ds1016g and 221 more | 2026-08-07 | N/A | 5.9 MEDIUM |
| A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. Successful exploitation may allow disclosure of provisioning information intended for a legitimate device. | |||||
| CVE-2025-15631 | 1 Tp-link | 218 Omada Ds1008x, Omada Ds1008x Firmware, Omada Ds1016g and 215 more | 2026-08-07 | N/A | 5.9 MEDIUM |
| A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments. | |||||
| CVE-2026-15427 | 1 Tp-link | 2 Archer Vx1800v, Archer Vx1800v Firmware | 2026-08-06 | N/A | 8.1 HIGH |
| An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation requires specific conditions such as TR-069 being enabled and ability to influence ACS-delivered commands, compromise or control an ACS server. Successful exploitation may allow arbitrary command execution with root privileges, resulting in complete compromise of the device. | |||||
| CVE-2026-15428 | 1 Tp-link | 2 Archer Vx1800v, Archer Vx1800v Firmware | 2026-08-06 | N/A | 8.8 HIGH |
| An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges. Successful exploitation may allow remote code execution and complete compromise of the device. | |||||
| CVE-2026-15429 | 1 Tp-link | 2 Archer Vx1800v, Archer Vx1800v Firmware | 2026-08-06 | N/A | 8.8 HIGH |
| A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data. An authenticated user with sufficient privileges may be able to modify account settings and gain elevated administrative privileges. | |||||
| CVE-2026-5040 | 1 Tp-link | 2 Deco M5, Deco M5 Firmware | 2026-08-06 | N/A | 6.7 MEDIUM |
| TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of authentication credentials, enabling unauthorized access to device management functions, depending on the privileges associated with the recovered password. The primary security impact is loss of confidentiality. | |||||
| CVE-2026-13230 | 1 Tp-link | 4 Kasa Ec70, Kasa Ec70 Firmware, Kasa Ec71 and 1 more | 2026-08-06 | N/A | 6.5 MEDIUM |
| An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted responses. The vulnerability impacts confidentiality only, with no evidence of integrity of availability impact. | |||||
| CVE-2026-9770 | 1 Tp-link | 4 Kasa Ec70, Kasa Ec70 Firmware, Kasa Ec71 and 1 more | 2026-08-06 | N/A | 5.3 MEDIUM |
| Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with access to the firmware image can extract the embedded key. Successful exploitation may allow an unauthenticated attacker on the same network to use this key in the web management service, compromising the confidentiality of encrypted communications. This may enable passive decryption of traffic or active man-in-the-middle (MITM) attacks | |||||
| CVE-2026-0651 | 1 Tp-link | 2 Tapo C260, Tapo C260 Firmware | 2026-08-04 | N/A | 7.8 HIGH |
| A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and falls back to using the raw path when normalization fails. An attacker can exploit this logic flaw by supplying crafted, URL encoded traversal sequences that bypass directory restrictions and allow access to files outside the intended web root. Successful exploitation may allow authenticated attackers to get disclosure of sensitive system files and credentials, while unauthenticated attackers may gain access to non-sensitive static assets. | |||||
| CVE-2026-0631 | 1 Tp-link | 2 Archer Be230, Archer Be230 Firmware | 2026-07-31 | N/A | 8.0 HIGH |
| An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID. This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420 and Archer AXE75 v1 < 1.5.6 Build 20260623. | |||||
| CVE-2026-30815 | 1 Tp-link | 2 Archer Ax53, Archer Ax53 Firmware | 2026-07-25 | N/A | 8.0 HIGH |
| An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification of configuration files, disclosure of sensitive information, or further compromise of device integrity. This issue affects AX53 v1.0: before 1.7.1 Build 20260213. | |||||
| CVE-2026-30818 | 1 Tp-link | 2 Archer Ax53, Archer Ax53 Firmware | 2026-07-25 | N/A | 8.0 HIGH |
| An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow the attacker to modify device configuration, access sensitive information, or further compromise system integrity. This issue affects AX53 v1.0: before 1.7.1 Build 20260213. | |||||
