tp-link has 37 CVEs on record between 2021 and 2026. Cadence is steady at roughly 6 per quarter. The busiest recent month was April 2026 with 6. The median CVSS is 8.0 (high), with 6 rated critical. 8% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-78 (12) and CWE-120 (3). Most affected products: archer_ax53_firmware (7), tl-wr840n_firmware (5), archer_be230_firmware (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 8% vs 1% corpus
- Median CVSS
- 8.0
- Publish → KEV
- —(1)
- Last 90 days
- 6 prev 7
Products
- archer_ax53_firmware 7
- tl-wr840n_firmware 5
- archer_be230_firmware 3
- er7212pc_firmware 2
- tapo_c200_firmware 2
- tl-sg2005_firmware 2
Worst active — by depth score
CVE-2021-41653Critical· 9.8The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.87CVE-2022-25060Critical· 9.8TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.80CVE-2022-25061Critical· 9.8TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.78CVE-2022-25064Critical· 9.8TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.73CVE-2022-30075High· 8.8In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.67
tp-link vulnerabilities
CVEs affecting tp-link, newest first. Open any entry for full detail, references, and exploit status.
37 CVEsRSS
CVE-2022-25061Critical· 9.8PoCTP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
CVE-2022-25060Critical· 9.8⚠ ExploitedPoCTP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
CVE-2021-41451High· 7.5A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send a specially crafted HTTP request and receive a misconfigured HTTP/0.9 response, potentia…
A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send a specially crafted HTTP request and receive a misconfigured HTTP/0.9 response, potentia…
CVE-2021-41450High· 7.5An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.
An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.
CVE-2021-41653Critical· 9.8⚠ ExploitedPoCThe PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
CVE-2021-31659High· 8.8TP-Link TL-SG2005, TL-SG2008, etc
TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information is placed in the URL, without any additional token authentication information. A maliciou…
CVE-2021-31658High· 8.1TP-Link TL-SG2005, TL-SG2008, etc
TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface that provides the "device description" function only judges the length of the received data, and does not filter special…