tp-link

523 tracked vulnerabilities.

CVE-2025-9293 HIGH
Certificate Validation Logic - Info Disclosure
Feb 13, 2026
CVSS 8.1
EPSS 0.00
CVE-2025-9292 HIGH
TP-Link Omada Cloud Controller - Permissive Cross-domain Security Policy with Untrusted Domains
Feb 13, 2026
CVSS 7.5
EPSS 0.00
CVE-2025-15557 HIGH
TP-Link Tapo H100 < 1.6.1 and Tapo P100 < 1.2.6 - Improper Certificate Validation
Feb 05, 2026
CVSS 8.8
EPSS 0.00
CVE-2025-15551 MEDIUM
TP-Link Archer MR200 v5.2, C20 v6, TL-WR850N v3, TL-WR845N v4 - RCE
Feb 05, 2026
CVSS 5.6
EPSS 0.00
CVE-2025-62673 HIGH
TP-Link Archer AX53 v1.0 < 1.3.1 Build 20241120 - Heap-based Buffer Overflow via Malformed Network Packet
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-62501 HIGH
TP-Link Archer AX53 <1.3.1 - Info Disclosure
Feb 03, 2026
CVSS 8.1
EPSS 0.00
CVE-2025-62405 HIGH
TP-Link Archer AX53 v1.0 < 1.3.1 Build 20241120 - Authenticated Heap-based Buffer Overflow via tmpserver Module
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-62404 HIGH
TP-Link Archer AX53 v1.0 <= 1.3.1 Build 20241120 - Authenticated Heap-based Buffer Overflow in tmpserver Module
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-61983 HIGH
TP-Link Archer AX53 v1.0 < 1.3.1 Build 20241120 - Authenticated Heap-based Buffer Overflow via tmpserver Network Packet
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-61944 HIGH
TP-Link Archer AX53 v1.0 < 1.3.1 Build 20241120 - Authenticated Heap-based Buffer Overflow via tmpserver Module
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-59487 HIGH
TP-Link Archer AX53 v1.0 < 1.3.1 Heap-based Buffer Overflow via tmpserver Packet
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-59482 HIGH
TP-Link Archer AX53 v1.0 < 1.3.1 Build 20241120 - Authenticated Heap-based Buffer Overflow via tmpserver Network Packet
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-58455 HIGH
TP-Link Archer AX53 <1.3.1 - Buffer Overflow
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-58077 HIGH
TP-Link Archer AX53 v1.0 < 1.3.1 Build 20241120 - Authenticated Heap-based Buffer Overflow via tmpserver Module
Feb 03, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-15548 MEDIUM
TP-Link VX800v Firmware < 800.0.18 - Missing Encryption of Sensitive Data in Web Interface
Jan 29, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-15543 MEDIUM
TP-Link VX800v Firmware < 800.0.11 - Improper Link Resolution in USB HTTP Access Path
Jan 29, 2026
CVSS 4.6
EPSS 0.00
CVE-2025-15542 MEDIUM
TP-Link VX800v Firmware < 800.0.12 - Denial of Service via SIP INVITE Flood
Jan 29, 2026
CVSS 5.3
EPSS 0.00
CVE-2025-15541 MEDIUM
TP-Link VX800v Firmware < 800.0.11 - Authenticated Symbolic Link Resolution
Jan 29, 2026
CVSS 6.3
EPSS 0.00
CVE-2025-13399 HIGH
TP-Link VX800v Firmware < 800.0.11 - Unauthenticated Weak AES Key Brute Force in Web Interface
Jan 29, 2026
CVSS 8.8
EPSS 0.00
CVE-2025-15545 MEDIUM
TP-Link Archer RE605X Firmware <= 1.2.10 - Command Injection via Backup Restore
Jan 29, 2026
CVSS 6.8
EPSS 0.00
CVE-2025-9522 MEDIUM
TP-Link Omada Controllers - Webhook Server-Side Request Forgery
Jan 26, 2026
CVSS 5.3
EPSS 0.00
CVE-2025-9521 MEDIUM
Omada Controllers - Privilege Escalation
Jan 26, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-9520 MEDIUM
TP-Link Omada Controllers - Administrator IDOR Owner Account Hijack
Jan 26, 2026
CVSS 6.8
EPSS 0.00
CVE-2025-14756 HIGH
TP-Link Archer MR600 v5 - Command Injection
Jan 26, 2026
CVSS 8.8
EPSS 0.00
CVE-2025-9290 MEDIUM
TP-Link Omada Controller and Devices - Authentication Bypass via Predictable Salt in Adoption Traffic
Jan 23, 2026
CVSS 5.9
EPSS 0.00