T

Tp-Link Security Vulnerabilities (CVE)

Explore vulnerabilities and security advisories affecting Tp-Link products.

13 known CVE vulnerabilities tracked

Critical
0
High
8
Medium
5
Low
0
None
0

Vulnerabilities By Year

Products Affected

All Tp-Link CVEs

CVE-2026-34127
4.8 medium

A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the SYSNAM configuration parameter during configuration file import. An attacker with administrator access can inject malicious script

Tl-Sg108Pe Firmware May 29, 2026
CVE-2026-34126
7.5 high

TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext without encryption. Bluetooth is only used during initialization. An attacker within the Bluetooth range

Tapo L535E Firmware May 28, 2026
CVE-2026-8697
8.8 high

Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web interface. This enables an attacker to brute-force valid credentials via SSH. Successful exploitati

Archer C64 Firmware May 28, 2026
CVE-2026-5509
7.2 high

An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary system commands through the web management interface. After successfully authenticating to the admin interface, an attacker can leverage the browser’s

Archer Be450 Firmware May 27, 2026
CVE-2026-3294
8.8 high

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administ

Re305 Firmware May 22, 2026
CVE-2018-25321
4.3 medium

TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers can modify port forwarding rules via VirtualServerRpm.htm or change WiFi security settings via Wlan

Tl-Wr720N Firmware May 17, 2026
CVE-2026-22226
7.2 high

A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration module on TP-Link Archer BE230 v1.2 and Archer AX73 v2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromis

Archer Be230 Firmware Feb 2, 2026
CVE-2025-14175
6.5 medium

A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and decrypt SSH traffic. Exploitation may expose sensitive information and compromise confidentiality.

Tl-Wr820N Firmware Dec 29, 2025
CVE-2025-8065
6.5 medium

A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer. It allowed a crafted SOAP request

Tapo C200 Firmware Dec 20, 2025
CVE-2025-14300
8.1 high

The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).

Tapo C200 Firmware Dec 20, 2025
CVE-2025-14299
6.5 medium

The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests to trigger excessive memory allocation, causing the device to crash and resultin

Tapo C200 Firmware Dec 20, 2025
CVE-2025-14738
7.5 high

Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922.

Tl-Wa850Re Firmware Dec 18, 2025
CVE-2025-14737
8.0 high

Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922.

Tl-Wa850Re Firmware Dec 18, 2025