Filtered by vendor Tp-link
Subscriptions
Total
597 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-75618 | 1 Tp-link | 2 Tapo C100 V5, Tapo C101 V5 | 2026-08-20 | N/A |
| Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful exploitation can disrupt live video streaming functionality and cause a temporary denial-of-service condition. | ||||
| CVE-2026-75619 | 1 Tp-link | 2 Tapo C100 V5, Tapo C101 V5 | 2026-08-20 | N/A |
| Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bounds heap writes. Successful exploitation can crash the RTSP service and trigger a device reboot, resulting in a temporary denial-of-service condition. | ||||
| CVE-2026-34118 | 1 Tp-link | 3 Tapo C520ws, Tapo C520ws Firmware, Tapo C520ws V2 | 2026-08-19 | 6.5 Medium |
| A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to insufficient boundary validation when handling externally supplied HTTP input. An attacker on the same network segment could trigger heap memory corruption conditions by sending crafted payloads that cause write operations beyond allocated buffer boundaries. Successful exploitation causes a Denial-of-Service (DoS) condition, causing the device’s process to crash or become unresponsive. | ||||
| CVE-2025-14300 | 1 Tp-link | 4 Tapo, Tapo C200, Tapo C200 Firmware and 1 more | 2026-08-14 | 8.1 High |
| The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS). | ||||
| CVE-2026-15141 | 1 Tp-link | 1 Td-w8961n | 2026-08-13 | N/A |
| The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information. | ||||
| CVE-2025-30240 | 1 Tp-link | 33 Eb810v(eu1) V1.0, Ex220(br) V1.0/1.20/1.28/1.29/1.8, Ex220(br) V2.0 and 30 more | 2026-08-12 | N/A |
| The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link. Successful exploitation may allow unauthorized read access to sensitive files within the device filesystem. | ||||
| CVE-2025-30241 | 1 Tp-link | 31 Eb210 Pro(eu1) 1.0, Eb210 Pro(us1) 1.0, Eb810v(eu1) V1.0 and 28 more | 2026-08-12 | N/A |
| Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions. An authenticated adjacent attacker may inject specially crafted input to execute arbitrary operation system commands with elevated privileges. Successful exploitation may allow execution of arbitrary system commands, potentially leading to full device compromise. | ||||
| CVE-2026-12001 | 1 Tp-link | 4 Archer C20 V6, Archer Mr200 V5, Tl-wr845n V4 and 1 more | 2026-08-11 | N/A |
| A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis. Successful exploitation could result in unauthorized access to privileged functions on affected devices. | ||||
| CVE-2025-30239 | 1 Tp-link | 65 Eb210 Pro(eu1) 1.0, Eb210 Pro(us1) 1.0, Eb810v(eu1) V1.0 and 62 more | 2026-08-11 | N/A |
| In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data. Successful exploitation may allow access to decrypted sensitive configuration data, including credentials and service-related information. | ||||
| CVE-2025-30237 | 1 Tp-link | 57 Aginet, Ex141(br) V1.0/1.9, Ex141(eu1) V1.0 and 54 more | 2026-08-11 | N/A |
| The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted requests to bypass authentication and directly invoke privileged functionality without valid credentials. This issue arises from improper enforcement of access control mechanisms on sensitive operations. Successful exploitation may allow an unauthenticated attacker to execute privileged operations and gain full control of the device. | ||||
| CVE-2025-30238 | 1 Tp-link | 59 Eb210 Pro(eu1) 1.0, Eb210 Pro(us1) 1.0, Eb810v(eu1) V1.0 and 56 more | 2026-08-11 | N/A |
| In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged operations. An attacker may perform administrative actions such as creating privileged accounts or modifying critical configuration settings. | ||||
| CVE-2026-9030 | 1 Tp-link | 1 Archer A6 V4 | 2026-08-10 | N/A |
| A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not properly synchronize or safely manage concurrent systool operations. By sending crafted systool instructions through the asynchronous request path, successful exploitation may cause the httpd process or device management service to crash and may result in temporary loss of access to the web management interface or device reboot. | ||||
| CVE-2026-9031 | 1 Tp-link | 1 Archer A6 V4 | 2026-08-10 | N/A |
| An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic. Successful exploitation may cause httpd process or device to crash, resulting in loss of access to the web interface and a denial-of-service condition. | ||||
| CVE-2025-9291 | 1 Tp-link | 221 Omada Access Point, Omada Ds1008x, Omada Ds1008x Firmware and 218 more | 2026-08-05 | 6.5 Medium |
| A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers. | ||||
| CVE-2025-15544 | 2 Tp-link, Tp Link | 231 Omada, Omada App, Omada Controller and 228 more | 2026-08-05 | 5.9 Medium |
| A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments. | ||||
| CVE-2025-15627 | 2 Tp-link, Tp Link | 228 Omada Controller, Omada Ds1008x, Omada Ds1008x Firmware and 225 more | 2026-08-05 | 7.5 High |
| A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications. | ||||
| CVE-2025-15628 | 1 Tp-link | 229 Omada Access Points, Omada Controller, Omada Ds1008x and 226 more | 2026-08-05 | 7.5 High |
| Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications. | ||||
| CVE-2025-15629 | 1 Tp-link | 228 Omada Access Point, Omada Controller, Omada Ds1008x and 225 more | 2026-08-05 | 7.5 High |
| A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be able to recover session encryption keys and decrypt affected communications. | ||||
| CVE-2025-15630 | 1 Tp-link | 228 Omada Access Point, Omada Controller, Omada Ds1008x and 225 more | 2026-08-05 | 5.9 Medium |
| A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. Successful exploitation may allow disclosure of provisioning information intended for a legitimate device. | ||||
| CVE-2025-15631 | 1 Tp-link | 222 Omada Access Point, Omada Ds1008x, Omada Ds1008x Firmware and 219 more | 2026-08-05 | 5.9 Medium |
| A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments. | ||||