tp-link
523 tracked vulnerabilities.
CVE-2025-9293
HIGH
Certificate Validation Logic - Info Disclosure
Feb 13, 2026
CVSS 8.1
EPSS 0.00
CVE-2025-9292
HIGH
TP-Link Omada Cloud Controller - Permissive Cross-domain Security Policy with Untrusted Domains
Feb 13, 2026
CVSS 7.5
EPSS 0.00
CVE-2025-15557
HIGH
TP-Link Tapo H100 < 1.6.1 and Tapo P100 < 1.2.6 - Improper Certificate Validation
Feb 05, 2026
CVSS 8.8
EPSS 0.00
CVE-2025-15551
MEDIUM
TP-Link Archer MR200 v5.2, C20 v6, TL-WR850N v3, TL-WR845N v4 - RCE
Feb 05, 2026
CVSS 5.6
EPSS 0.00
CVE-2025-62673
HIGH
TP-Link Archer AX53 v1.0 < 1.3.1 Build 20241120 - Heap-based Buffer Overflow via Malformed Network Packet
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-62501
HIGH
TP-Link Archer AX53 <1.3.1 - Info Disclosure
Feb 03, 2026
CVSS 8.1
EPSS 0.00
CVE-2025-62405
HIGH
TP-Link Archer AX53 v1.0 < 1.3.1 Build 20241120 - Authenticated Heap-based Buffer Overflow via tmpserver Module
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-62404
HIGH
TP-Link Archer AX53 v1.0 <= 1.3.1 Build 20241120 - Authenticated Heap-based Buffer Overflow in tmpserver Module
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-61983
HIGH
TP-Link Archer AX53 v1.0 < 1.3.1 Build 20241120 - Authenticated Heap-based Buffer Overflow via tmpserver Network Packet
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-61944
HIGH
TP-Link Archer AX53 v1.0 < 1.3.1 Build 20241120 - Authenticated Heap-based Buffer Overflow via tmpserver Module
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-59487
HIGH
TP-Link Archer AX53 v1.0 < 1.3.1 Heap-based Buffer Overflow via tmpserver Packet
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-59482
HIGH
TP-Link Archer AX53 v1.0 < 1.3.1 Build 20241120 - Authenticated Heap-based Buffer Overflow via tmpserver Network Packet
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-58455
HIGH
TP-Link Archer AX53 <1.3.1 - Buffer Overflow
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-58077
HIGH
TP-Link Archer AX53 v1.0 < 1.3.1 Build 20241120 - Authenticated Heap-based Buffer Overflow via tmpserver Module
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-15548
MEDIUM
TP-Link VX800v Firmware < 800.0.18 - Missing Encryption of Sensitive Data in Web Interface
Jan 29, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-15543
MEDIUM
TP-Link VX800v Firmware < 800.0.11 - Improper Link Resolution in USB HTTP Access Path
Jan 29, 2026
CVSS 4.6
EPSS 0.00
CVE-2025-15542
MEDIUM
TP-Link VX800v Firmware < 800.0.12 - Denial of Service via SIP INVITE Flood
Jan 29, 2026
CVSS 5.3
EPSS 0.00
CVE-2025-15541
MEDIUM
TP-Link VX800v Firmware < 800.0.11 - Authenticated Symbolic Link Resolution
Jan 29, 2026
CVSS 6.3
EPSS 0.00
CVE-2025-13399
HIGH
TP-Link VX800v Firmware < 800.0.11 - Unauthenticated Weak AES Key Brute Force in Web Interface
Jan 29, 2026
CVSS 8.8
EPSS 0.00
CVE-2025-15545
MEDIUM
TP-Link Archer RE605X Firmware <= 1.2.10 - Command Injection via Backup Restore
Jan 29, 2026
CVSS 6.8
EPSS 0.00
CVE-2025-9522
MEDIUM
TP-Link Omada Controllers - Webhook Server-Side Request Forgery
Jan 26, 2026
CVSS 5.3
EPSS 0.00
CVE-2025-9521
MEDIUM
Omada Controllers - Privilege Escalation
Jan 26, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-9520
MEDIUM
TP-Link Omada Controllers - Administrator IDOR Owner Account Hijack
Jan 26, 2026
CVSS 6.8
EPSS 0.00
CVE-2025-14756
HIGH
TP-Link Archer MR600 v5 - Command Injection
Jan 26, 2026
CVSS 8.8
EPSS 0.00
CVE-2025-9290
MEDIUM
TP-Link Omada Controller and Devices - Authentication Bypass via Predictable Salt in Adoption Traffic
Jan 23, 2026
CVSS 5.9
EPSS 0.00
Products
tl-wr886n_firmware 39
tl-wr841n_firmware 38
er5110g_firmware 25
er5120g_firmware 25
er5510g_firmware 25
er5520g_firmware 25
r4149g_firmware 25
r4239g_firmware 25
r4299g_firmware 25
r473_firmware 25
r473g_firmware 25
r473gp-ac_firmware 25
r473p-ac_firmware 25
r478\+_firmware 25
r478_firmware 25
r478g\+_firmware 25
r483_firmware 25
r483g_firmware 25
r488_firmware 25
war1300l_firmware 25
war1750l_firmware 25
war2600l_firmware 25
war302_firmware 25
war450_firmware 25
war450l_firmware 25
war458_firmware 25
war458l_firmware 25
war900l_firmware 25
wvr1300g_firmware 25
wvr1300l_firmware 25
Quick Filters