← All vendors

tp-link

45 known vulnerabilities affecting tp-link products.

Products

omada_er707-m2 7 omada_er707-m2_firmware 7 omada_fusion_2.5g 7 omada_fusion_2.5g_firmware 7 archer_ax53 6 archer_ax53_firmware 6 tapo_c520ws 6 tapo_c520ws_firmware 6 omada_s6500-24gp4xf 5 omada_s6500-24gp4xf_firmware 5 omada_s6500-24mpp4y 5 omada_s6500-24mpp4y_firmware 5 omada_s6500-48g6xf 5 omada_s6500-48g6xf_firmware 5 omada_s6500-48gp6xf 5 omada_s6500-48gp6xf_firmware 5 omada_s6500-48mpp6y 5 omada_s6500-48mpp6y_firmware 5 omada_s7500-24y4c 5 omada_s7500-24y4c_firmware 5 omada_s7500-26xf6y 5 omada_s7500-26xf6y_firmware 5 omada_er605 5 omada_er605_firmware 5

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2023-50224 Act now 15.6% 6.5 TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vul…
CVE-2026-19586 High 5.7% 9.8 A pre-authentication OS command injection vulnerability has been identified in O…
CVE-2026-30815 Medium 1.6% 8.0 An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX…
CVE-2026-0631 Medium 1.4% 8.0 An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) …
CVE-2026-30818 Medium 1.2% 8.0 An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX…
CVE-2026-9044 Medium 1.2% 8.0 An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 …
CVE-2026-15428 Medium 1.0% 8.8 An OS command injection vulnerability exists in Archer VX800v v1 due to insuffic…
CVE-2026-15429 Medium 0.8% 8.8 A privilege escalation vulnerability exists in the HTTP authentication component…
CVE-2025-15608 Medium 0.6% 9.8 This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient i…
CVE-2026-15427 Medium 0.6% 8.1 An OS command injection vulnerability exists in the TR-069 / CWMP management int…
CVE-2026-15314 Medium 0.5% 7.5 Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerabi…
CVE-2026-34121 Medium 0.4% 8.8 An authentication bypass vulnerability within the HTTP handling of the DS config…
CVE-2026-8619 Medium 0.4% 7.5 An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-…
CVE-2026-30814 Medium 0.4% 8.0 A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.…
CVE-2026-3294 Medium 0.4% 8.8 An authentication logic vulnerability in multiple TP-Link range extenders allows…
CVE-2025-14300 Medium 0.4% 8.1 The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectA…
CVE-2025-15627 Medium 0.3% 7.5 A cryptographic weakness exists in the Omada adoption protocol.  The protocol re…
CVE-2026-0651 Medium 0.3% 7.8 A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C21…
CVE-2026-15315 Medium 0.3% 8.8 Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within…
CVE-2026-19683 Medium 0.3% 7.4 A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada …
CVE-2025-15628 Medium 0.2% 7.5 Affected Omada devices rely on embedded certificates that are shared across depl…
CVE-2025-15629 Medium 0.2% 7.5 A cryptographic weakness exists in the Omada adoption protocol where session enc…
CVE-2026-75616 Low 3.1% 6.8 An OS command injection vulnerability exists in the web management interface of …
CVE-2026-13230 Low 0.4% 6.5 An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 a…
CVE-2026-34118 Low 0.4% 6.5 A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C…
CVE-2026-9770 Low 0.4% 5.3 Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key st…
CVE-2026-30817 Low 0.3% 5.7 An external configuration control vulnerability in the OpenVPN module of TP-Link…
CVE-2026-1871 Low 0.3% 6.5 TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authent…
CVE-2026-34124 Low 0.3% 6.5 A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 wit…
CVE-2026-30816 Low 0.3% 5.7 An external control of configuration vulnerability in the OpenVPN module of TP-L…
CVE-2026-75619 Low 0.3% 5.7 Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTS…
CVE-2026-34122 Low 0.3% 6.5 A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520W…
CVE-2026-34127 Low 0.2% 4.8 A stored cross-site scripting (XSS) vulnerability has been identified in the web…
CVE-2026-75618 Low 0.2% 6.5 Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP …
CVE-2026-34119 Low 0.2% 6.5 A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS…
CVE-2026-34120 Low 0.2% 6.5 A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS…
CVE-2026-15316 Low 0.2% 6.5 An improper input validation vulnerability in the configuration service for proc…
CVE-2026-5511 Low 0.2% 2.7 In the web management interface of Archer AX72 (SG) v1, the network diagnostic f…
CVE-2025-15544 Low 0.2% 5.9 A cryptographic weakness exists in the Omada device adoption process.  During ad…
CVE-2025-15630 Low 0.2% 5.9 A race condition exists in the cloud-based Omada device adoption process when an…
CVE-2026-9033 Low 0.2% 4.3 An unauthenticated attacker with network access to the captive portal service of…
CVE-2025-15631 Low 0.2% 5.9 A cryptographic weakness exists in affected Omada devices where site credentials…
CVE-2025-9291 Low 0.1% 6.5 A certification validation weakness exists in communication between affected Oma…
CVE-2026-15141 Low 0.1% 5.7 The web interface of the affected device relies on the HTTP referrer header as p…
CVE-2026-5040 Low 0.1% 6.7 TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credenti…