VulnSea

tp-link has 35 CVEs on record between 2021 and 2026. Cadence is steady at roughly 6 per quarter. The busiest recent month was April 2026 with 6. The median CVSS is 8.0 (high), with 6 rated critical. 9% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-78 (12) and CWE-787 (3). Most affected products: archer_ax53_firmware (6), tl-wr840n_firmware (5), archer_be230_firmware (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
9% vs 1% corpus
Median CVSS
8.0
Publish → KEV
(1)
Last 90 days
6 prev 7

Products

  • archer_ax53_firmware 6
  • tl-wr840n_firmware 5
  • archer_be230_firmware 3
  • er7212pc_firmware 2
  • tl-sg2005_firmware 2
  • tl-wdr7660_firmware 2
35
Total CVEs
6
Critical
1
CISA KEV
3
Exploited

tp-link vulnerabilities

CVEs affecting tp-link, newest first. Open any entry for full detail, references, and exploit status.

35 CVEsRSS

CVE-2026-9033Medium· 4.3
1mo ago

An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions

An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users …

Sunlittp-link · er7212pc_firmwareEPSS 0.20%via NVD
CVE-2026-19683High· 7.4
1mo ago

A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways

A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can o…

Twilighttp-link · er7212pc_firmwareEPSS 0.25%via NVD
CVE-2026-75616Medium· 6.8PoC
1mo ago

An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations

An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation…

Twilighttp-link · archer_c20_firmwareEPSS 3.1%via NVD
CVE-2026-15141Medium· 5.7
1mo ago

The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficie…

The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficie…

Sunlittp-link · tl-wr820n_firmwareEPSS 0.12%via NVD
CVE-2026-15314High· 7.5
1mo ago

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflo…

Twilighttp-link · tapo_p110_firmwareEPSS 0.50%via NVD
CVE-2026-9044High· 8.0
1mo ago

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN cl…

Twilighttp-link · archer_axe75_firmwareEPSS 1.2%via NVD
CVE-2026-3294High· 8.8
4mo ago

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Suc…

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Suc…

Twilighttp-link · re305_firmwareEPSS 0.40%via NVD
CVE-2026-30818High· 8.0
5mo ago

An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient inpu…

An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient inpu…

Twilighttp-link · archer_ax53_firmwareEPSS 1.2%via NVD
CVE-2026-30817Medium· 5.7
5mo ago

An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed

An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may a…

Sunlittp-link · archer_ax53_firmwareEPSS 0.34%via NVD
CVE-2026-30816Medium· 5.7
5mo ago

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may…

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may…

Sunlittp-link · archer_ax53_firmwareEPSS 0.29%via NVD
CVE-2026-30815High· 8.0
5mo ago

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient inp…

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient inp…

Twilighttp-link · archer_ax53_firmwareEPSS 1.6%via NVD
CVE-2026-30814High· 8.0
5mo ago

A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file…

A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file…

Twilighttp-link · archer_ax53_firmwareEPSS 0.42%via NVD
CVE-2026-34118Medium· 6.5
5mo ago

A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to insufficient …

A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to insufficient …

Sunlittp-link · tapo_c520ws_firmwareEPSS 0.37%via NVD
CVE-2025-15608Critical· 9.8
6mo ago

This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected servi…

This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected servi…

Midnighttp-link · archer_ax53_firmwareEPSS 0.64%via NVD
CVE-2026-3227Medium· 6.8PoC
6mo ago

A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command

A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an au…

Twilighttp-link · tl-wr802n_firmwareEPSS 1.9%via NVD
CVE-2026-0651High· 7.8PoC
7mo ago

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and fa…

Midnighttp-link · tapo_c260_firmwareEPSS 0.32%via NVD
CVE-2026-22223High· 8.0
7mo ago

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrati…

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrati…

Twilighttp-link · archer_be230_firmwareEPSS 1.5%via NVD
CVE-2026-22221High· 8.0
7mo ago

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrativ…

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrativ…

Twilighttp-link · archer_be230_firmwareEPSS 1.4%via NVD
CVE-2026-0631High· 8.0
7mo ago

An OS Command Injection vulnerability in OpenVPN modules in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1 allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain…

An OS Command Injection vulnerability in OpenVPN modules in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1 allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain…

Twilighttp-link · archer_be230_firmwareEPSS 1.5%via NVD
CVE-2025-14300High· 8.1
9mo ago

The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authentication

The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi config…

Twilighttp-link · tapo_c200_firmwareEPSS 0.37%via NVD
CVE-2023-50224Medium· 6.5CISA KEV0day
2y ago

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Au…

Midnighttp-link · tl-wr841n_firmwareEPSS 16%via NVD
CVE-2021-42232Critical· 9.8
4y ago

TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp

TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an at…

Midnighttp-link · archer_a7_firmwareEPSS 4.3%via NVD
CVE-2022-30024High· 8.8PoC
4y ago

A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network

A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network. T…

Midnighttp-link · tl-wr841_firmwareEPSS 2.1%via NVD
CVE-2022-30075High· 8.8PoC
4y ago

In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.

In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.

Midnighttp-link · archer_ax50_firmwareEPSS 34%via NVD
CVE-2022-26988High· 7.8
4y ago

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution.

Twilighttp-link · tl-wdr7660_firmwareEPSS 1.4%via NVD
CVE-2022-26987High· 7.8
4y ago

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.

Twilighttp-link · tl-wdr7660_firmwareEPSS 1.4%via NVD
CVE-2022-25064Critical· 9.8PoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

Abyssaltp-link · tl-wr840n_firmwareEPSS 36%via NVD
CVE-2022-25062High· 7.5PoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Midnighttp-link · tl-wr840n_firmwareEPSS 3.5%via NVD
CVE-2022-25061Critical· 9.8PoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

Abyssaltp-link · tl-wr840n_firmwareEPSS 59%via NVD
CVE-2022-25060Critical· 9.8⚠ ExploitedPoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

Abyssaltp-link · tl-wr840n_firmwareEPSS 40%via NVD
tp-link vulnerabilities (CVEs) · VulnSea