Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices
TP-Link CVEs
23 high and critical vulnerabilities covered by CVE Brief since 2025-09-02, each with independent analyst commentary.
← All vendors RSS feed Watch this vendorProfile
Last 12 months
20 CVEs in the last 12 months
Products
- HB810(US2) V1.0/1.6/2.0/2.64
- Archer BE800 V12
- Omada Gateways2
- Kasa EC71 v41
- AXE75 V11
- Archer C64 v1.01
- Archer BE3600 v11
- HS103P3 / HS103P4 v51
16 products in total
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to i...
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication a...
A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1
Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol
A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds c...
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a lo...
A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlle...
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system...
The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5300 v3
The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow
A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient valid...
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability - Active in CISA KEV catalog.
A certification validation weakness exists in communication between affected Omada devices and cloud controllers
Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to sys...
In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an...
In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged opera...
The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certai...
Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices
TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability - Active in CISA KEV catalog.
TP-Link AX1800 WiFi 6 Router (Archer AX21) devices allow unauthenticated attackers (on the LAN) to execute arbitrary code as root via the db_dir field...
TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.