VulnSea

tp-link has 37 CVEs on record between 2021 and 2026. Cadence is steady at roughly 6 per quarter. The busiest recent month was April 2026 with 6. The median CVSS is 8.0 (high), with 6 rated critical. 8% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-78 (12) and CWE-120 (3). Most affected products: archer_ax53_firmware (7), tl-wr840n_firmware (5), archer_be230_firmware (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
8% vs 1% corpus
Median CVSS
8.0
Publish → KEV
—(1)
Last 90 days
6 prev 7

Products

  • archer_ax53_firmware 7
  • tl-wr840n_firmware 5
  • archer_be230_firmware 3
  • er7212pc_firmware 2
  • tapo_c200_firmware 2
  • tl-sg2005_firmware 2
37
Total CVEs
6
Critical
1
CISA KEV
3
Exploited

tp-link vulnerabilities

CVEs affecting tp-link, newest first. Open any entry for full detail, references, and exploit status.

37 CVEsRSS

CVE-2022-25061Critical· 9.8PoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

▾ Abyssaltp-link · tl-wr840n_firmwareEPSS 59%via NVD
CVE-2022-25060Critical· 9.8⚠ ExploitedPoC
4y ago

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

▾ Abyssaltp-link · tl-wr840n_firmwareEPSS 40%via NVD
CVE-2021-41451High· 7.5
4y ago

A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send a specially crafted HTTP request and receive a misconfigured HTTP/0.9 response, potentia…

A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send a specially crafted HTTP request and receive a misconfigured HTTP/0.9 response, potentia…

▾ Twilighttp-link · archer_ax10_firmwareEPSS 2.4%via NVD
CVE-2021-41450High· 7.5
4y ago

An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.

An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.

▾ Twilighttp-link · archer_ax10_v1_firmwareEPSS 1.8%via NVD
CVE-2021-41653Critical· 9.8⚠ ExploitedPoC
4y ago

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.

▾ Abyssaltp-link · tl-wr840n_firmwareEPSS 76%via NVD
CVE-2021-31659High· 8.8
5y ago

TP-Link TL-SG2005, TL-SG2008, etc

TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information is placed in the URL, without any additional token authentication information. A maliciou…

▾ Twilighttp-link · tl-sg2005_firmwareEPSS 0.56%via NVD
CVE-2021-31658High· 8.1
5y ago

TP-Link TL-SG2005, TL-SG2008, etc

TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface that provides the "device description" function only judges the length of the received data, and does not filter special…

▾ Twilighttp-link · tl-sg2005_firmwareEPSS 1.0%via NVD
tp-link vulnerabilities (CVEs) — page 2 · VulnSea