tp-link

523 tracked vulnerabilities.

CVE-2017-15614 HIGH
TP-Link WVR WAR and ER Firmware - Authenticated Command Injection via pptp_client.lua new-outif Variable
Jan 11, 2018
CVSS 7.2
EPSS 0.01
CVE-2017-15613 HIGH
TP-Link WVR WAR and ER Firmware - Authenticated Command Injection via cmxddns.lua new-interface Variable
Jan 11, 2018
CVSS 7.2
EPSS 0.01
CVE-2017-17747 MEDIUM
TP-Link TL-SG108E v1.0.0 - Unauthenticated Denial of Service via Device Logout Functionality
Dec 20, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-17746 MEDIUM
TP-Link TL-SG108E Firmware 1.0.0 - Missing Authentication for Critical Function via NAT Gateway IP
Dec 20, 2017
CVSS 6.8
EPSS 0.00
CVE-2017-17745 MEDIUM
TP-Link TL-SG108E 1.0.0 - Authenticated Cross-Site Scripting via sysName Parameter
Dec 20, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-17758 HIGH
TP-Link TL-WVR and TL-WAR Firmware - Authenticated Remote Code Execution via Dhcps Interface Field
Dec 19, 2017
CVSS 8.8
EPSS 0.01
CVE-2017-17757 HIGH
TP-Link TL-WVR and TL-WAR Firmware - Authenticated Remote Code Execution via Interface Field
Dec 19, 2017
CVSS 8.8
EPSS 0.01
CVE-2017-16960 HIGH
TP-Link TL-WVR/TL-WAR/TL-ER/TL-R - Command Injection
Nov 27, 2017
CVSS 8.8
EPSS 0.01
CVE-2017-16959 MEDIUM
TP-Link TL-WVR/TL-WAR/TL-ER/TL-R - Info Disclosure
Nov 27, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-16958 HIGH
TP-Link TL-WVR,TL-WAR,TL-ER,TL-R - Command Injection
Nov 27, 2017
CVSS 8.8
EPSS 0.01
CVE-2017-16957 HIGH
TP-Link TL-WVR/TL-WAR/TL-ER/TL-R - Command Injection
Nov 27, 2017
CVSS 8.8
EPSS 0.03
CVE-2017-13772 HIGH
TP-Link WR940N Hardware v4 - Authenticated Remote Code Execution via PingIframeRpm.htm or WanStaticIpV6CfgRpm.htm
Oct 23, 2017
CVSS 8.8
EPSS 0.53
CVE-2017-15291 MEDIUM
TP-LINK TL-MR3220 Firmware - Stored Cross-Site Scripting via Wireless MAC Filtering Description Field
Oct 20, 2017
CVSS 6.1
EPSS 0.01
CVE-2017-11519 CRITICAL
TP-Link Archer C9(UN) - Privilege Escalation
Jul 21, 2017
CVSS 9.8
EPSS 0.13
CVE-2017-10796 MEDIUM
TP-Link NC250 Firmware < 1.2.1 - Unauthenticated Video and Audio Access via RTSP URL
Jul 02, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-9466 CRITICAL
TP-Link WR841N V8 - Info Disclosure
Jun 26, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-8220 CRITICAL
TP-Link C2 and C20i < 0.9.1_4.2_v0032.0_build_160706 - Remote Code Execution via HTTP POST Host Parameter
Apr 25, 2017
CVSS 9.9
EPSS 0.04
CVE-2017-8219 MEDIUM
TP-Link C2 and C20i Firmware < 0.9.1_4.2_v0032.0_build_160706 - Denial of Service via Crafted Cookie Header
Apr 25, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-8218 CRITICAL
vsftpd on TP-Link C2/C20i - Auth Bypass
Apr 25, 2017
CVSS 9.8
EPSS 0.01
CVE-2017-8217 MEDIUM
TP-Link C2 and C20i < 0.9.1_4.2_v0032.0_build_160706 - Missing Authorization via SNMP
Apr 25, 2017
CVSS 5.3
EPSS 0.00
CVE-2017-8078 MEDIUM
TP-Link TL-SG108E Firmware 1.1.2 Build 20141017 Rel.50749 - Unauthenticated Firmware Upgrade via httpupg.cgi
Apr 23, 2017
CVSS 5.3
EPSS 0.00
CVE-2017-8077 HIGH
TP-Link TL-SG108E Firmware 1.1.2 Build 20141017 Rel.50749 - Use of Hard-coded Credentials
Apr 23, 2017
CVSS 7.5
EPSS 0.00
CVE-2017-8076 CRITICAL
TP-Link TL-SG108E Firmware 1.1.2 Build 20141017 Rel.50749 - Inadequate Encryption Strength
Apr 23, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-8075 CRITICAL
TP-Link TL-SG108E Firmware 1.1.2 Build 20141017 Rel.50749 - Cleartext Password Exposure in Log Files
Apr 23, 2017
CVSS 9.8
EPSS 0.02
CVE-2017-8074 CRITICAL
TP-Link TL-SG108E Firmware 1.1.2 Build 20141017 Rel.50749 - Sensitive Information Exposure in Log Files
Apr 23, 2017
CVSS 9.8
EPSS 0.01