Tp Link Systems Inc.
43 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-76784
HIGH 8.7
Hs103p3 / Hs103p4 V5 — Multiple
TP-Link Kasa smart home devices contain insufficient cryptographic protections
in the local device co…
2026-08-26
CVE-2026-15469
HIGH 7.7
Deco Xe75 V3 / Xe5300 V3.6/ We10800 V3.6 — The use of
hard-coded cryptographic key vulnerability has been identified in the mesh
functionality of Deco XE…
2026-08-24
CVE-2026-16348
HIGH 8.5
Archer Be800 V1 — An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administra…
2026-08-24
CVE-2026-78541
HIGH 8.5
Archer Be3600 V1 — A stored OS
command injection vulnerability exists in the parent-control module of TP-Link
Archer BE3600 V1. A…
2026-08-24
CVE-2026-9254
HIGH 8.7
Archer Be800 V1 — An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer B…
2026-08-24
CVE-2026-17250
HIGH 8.5
Tl Mr6400 V7.0 — A
stack-based buffer overflow vulnerability exists in the firmware update
functionality of TL-MR6400 v7 due to…
2026-08-21
CVE-2026-17251
HIGH 7.1
Tl Mr6400 V7.0 — A NULL
pointer dereference vulnerability exists in the HTTP request parsing
functionality of
TL-MR6400 v7. An…
2026-08-21
CVE-2026-17252
HIGH 7.1
Tl Mr6400 V7.0 — A
stack-based out-of-bounds write vulnerability exists in the login request
handling functionality of the admi…
2026-08-21
CVE-2026-19586
CRITICAL 9.3
Er7212pc V2 — A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to op…
2026-08-20
CVE-2026-19683
MEDIUM 6.3
Er7212pc V2 — A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication…
2026-08-20
CVE-2026-9033
MEDIUM 6
Er7212pc V2 — An unauthenticated attacker with network access to the captive portal service of an affected device can termin…
2026-08-20
CVE-2026-75616
HIGH 8.5
Archer C20 V6 — An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when pr…
2026-08-19
CVE-2026-75618
HIGH 7.1
Tapo C100 V5 — Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the lo…
2026-08-19
CVE-2026-75619
MEDIUM 6.9
Tapo C100 V5 — Tapo
C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP
service. An authenticated at…
2026-08-19
CVE-2026-8619
HIGH 7.1
Tl Mr100 V3.2 — An
unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-…
2026-08-19
CVE-2026-15315
HIGH 8.7
Tapo C200 V5 — Tapo C120 v1 and C200 v5
contain an improper authentication vulnerability within the login
authentication veri…
2026-08-18
CVE-2026-15316
HIGH 7.1
Tapo C200 V5 — An improper input
validation vulnerability in the configuration service for processing encrypted
credential da…
2026-08-18
CVE-2026-15141
MEDIUM 5.3
Tl Wr820n V2 — The web
interface of the affected
device relies on the HTTP referrer header as part of
request validation. Re…
2026-08-12
CVE-2026-12339
MEDIUM 6.9
Tl Mr6400 V5.3 — A Zip Slip vulnerability in the WebUI ISP
Upgrade functionality allows arbitrary file write via a crafted arch…
2026-08-10
CVE-2025-30237
HIGH 8.7
Hb810(Us2) V1.0/1.6/2.0/2.6 — The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication
checks…
2026-08-10
CVE-2025-30238
HIGH 8.6
Hb810(Us2) V1.0/1.6/2.0/2.6 — In affected TP-Link Aginet devices, insufficient
authorization validation allows authenticated low-privileged …
2026-08-10
CVE-2025-30239
HIGH 8.5
Hb810(Us2) V1.0/1.6/2.0/2.6 — In affected TP-Link Aginet devices, use of
hardcoded cryptographic keys embedded in the firmware to protect se…
2026-08-10
CVE-2025-30240
MEDIUM 5.1
Hb810(Us2) V1.0/1.6/2.0/2.6 — The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage
de…
2026-08-10
CVE-2025-30241
HIGH 8.6
Hb810(Us2) V1.0/1.6/2.0/2.6 — Certain web
interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied…
2026-08-10
CVE-2026-9030
MEDIUM 6.8
Archer A6 V4 — A denial-of-service
vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool
instr…
2026-08-07
CVE-2026-9031
MEDIUM 6.8
Archer A6 V4 — An input validation
vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation
of user-s…
2026-08-07
CVE-2026-15314
HIGH 7.1
P110 V1 — Tapo P110 v1
smart Wi-Fi Plug contains an improper boundary validation vulnerability in the
handling of authen…
2026-08-04
CVE-2025-15544
MEDIUM 6.9
Omada Gateways — A cryptographic
weakness exists in the Omada device adoption process. During adoption, authentication credent…
2026-08-03
CVE-2025-15627
MEDIUM 6.9
Omada Gateways — A cryptographic
weakness exists in the Omada adoption protocol.
The protocol relies on hard-coded cryptograph…
2026-08-03
CVE-2025-15628
HIGH 8.2
Omada Gateways — Affected
Omada devices rely on embedded certificates that are shared across deployments
to establish trust bet…
2026-08-03
CVE-2025-15629
MEDIUM 6.9
Omada Gateways — A cryptographic
weakness exists in the Omada adoption protocol where session encryption keys
used to protect c…
2026-08-03
CVE-2025-15630
MEDIUM 5.8
Omada Gateways — A race
condition exists in the cloud-based Omada device adoption process when an
attacker may be able to inter…
2026-08-03
CVE-2025-15631
MEDIUM 5.7
Omada Gateways — A
cryptographic weakness exists in affected Omada devices where site credentials
are protected using a legacy …
2026-08-03
CVE-2025-9291
HIGH 7.7
Omada Gateways — A
certification validation weakness exists in communication between affected
Omada devices and cloud controlle…
2026-08-03
CVE-2026-9044
HIGH 8.5
Axe75 V1 — An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability…
2026-07-31
CVE-2026-12935
HIGH 8.7
Tl Wr940n V6 — The
TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking
module that can lead to a sta…
2026-07-29
CVE-2026-12001
MEDIUM 5.2
Tl Wr850n V3 — A hardcoded credential
vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR85…
2026-07-27
CVE-2026-13230
MEDIUM 5.3
Kasa Ec71 V4 — An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discov…
2026-07-15
CVE-2026-9770
HIGH 8.6
Kasa Ec71 V4 — Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem…
2026-07-15
CVE-2026-15427
HIGH 8.6
Archer Vx1800v V1 — An OS command
injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 du…
2026-07-14
CVE-2026-15428
HIGH 8.5
Archer Vx1800v V1 — An OS
command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of
the…
2026-07-14
CVE-2026-15429
MEDIUM 5.1
Archer Vx1800v V1 — A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Imprope…
2026-07-14
CVE-2026-5040
HIGH 7.1
Deco M5 Deco M5 V1 — TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains …
2026-07-14