16 Total CVEs
13 AI Analyzed
3 CISA KEV
3 Critical
All Vendors
Showing 1-16 of 16 CVEs
CVE-2026-9770
Analyzed
8.6
TP-Link Kasa EC71 v4 and EC70 v4

Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices

2026-07-15
CVE-2026-9044
Analyzed
8.5
TP-Link AXE75 V1

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers

2026-08-01
CVE-2026-8697
Analyzed
8.8
TP-Link Archer C64

Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication a...

2026-06-04
CVE-2026-3294
Analyzed
8.8
TP-Link Range Extenders

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a lo...

2026-06-02
CVE-2026-12935
Analyzed
8.7
TP-Link TL-WR940N v6

The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow

2026-07-30
CVE-2026-11834
Analyzed
8.7
TP-Link Archer MR200

A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient valid...

2026-06-23
CVE-2025-9377
KEV
9.5
TP-Link Multiple Routers

TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability - Active in CISA KEV catalog.

2025-09-03
CVE-2025-9291
Analyzed
7.7
TP-Link Omada Gateways

A certification validation weakness exists in communication between affected Omada devices and cloud controllers

2026-08-04
CVE-2025-30241
Analyzed
8.6
TP-Link Aginet HB810, HB710, HB610

Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to sys...

2026-08-11
CVE-2025-30239
Analyzed
8.5
TP-Link Aginet HB810, HB710, HB610

In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an...

2026-08-11
CVE-2025-30238
Analyzed
8.6
TP-Link Aginet HB810, HB710, HB610

In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged opera...

2026-08-11
CVE-2025-30237
Analyzed
8.7
TP-Link Aginet devices

The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certai...

2026-08-11
CVE-2025-15628
Analyzed
8.2
TP-Link Omada Gateways

Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices

2026-08-04
CVE-2023-50224
KEV
9.5
TP-Link TL-WR841N

TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability - Active in CISA KEV catalog.

2025-09-03
CVE-2023-28760
Analyzed
7.5
TP-Link Multiple Products

TP-Link AX1800 WiFi 6 Router (Archer AX21) devices allow unauthenticated attackers (on the LAN) to execute arbitrary code as root via the db_dir field...

2025-10-02
CVE-2020-24363
KEV
9.5
TP-Link TL-WA855RE

TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.

2025-09-02