Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

TP-Link Systems INC. — Vulnerabilities & Security Advisories 156

Browse all 156 CVE security advisories affecting TP-Link Systems INC.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TP-Link Systems Inc. operates as a leading manufacturer of consumer networking hardware, primarily producing wireless routers, switches, and smart home devices for residential and small business environments. The company’s firmware and web management interfaces have historically been susceptible to critical vulnerability classes, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These weaknesses often stem from insufficient input validation and hardcoded credentials within embedded web servers, allowing attackers to gain unauthorized administrative access or execute arbitrary commands on affected devices. Notable incidents include the discovery of backdoors in specific router models and widespread exploitation of unpatched RCE vulnerabilities that facilitated botnet recruitment. With over 100 CVEs on record, the firm faces ongoing scrutiny regarding its patch management lifecycle and the security of its IoT ecosystem, necessitating rigorous updates to mitigate persistent risks associated with its extensive global user base.

CVE IDTitleCVSSSeverityPublished
CVE-2026-15141 Referer Validation Bypass in TL-WR820N Web Management Interface — TL-WR820N v2CWE-346 5.3 Medium2026-08-12
CVE-2025-30241 OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices — HB810(US2) V1.0/1.6/2.0/2.6CWE-78 8.6 High2026-08-10
CVE-2025-30240 Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP-Link Aginet Devices — HB810(US2) V1.0/1.6/2.0/2.6CWE-59 5.1 Medium2026-08-10
CVE-2025-30239 Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet Devices — HB810(US2) V1.0/1.6/2.0/2.6CWE-321 8.5 High2026-08-10
CVE-2025-30238 Privilege Escalation via Improper Authorization in User Management in multiple TP-Link Aginet Devices — HB810(US2) V1.0/1.6/2.0/2.6CWE-863 8.6 High2026-08-10
CVE-2025-30237 Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet Devices — HB810(US2) V1.0/1.6/2.0/2.6CWE-862 8.7 High2026-08-10
CVE-2026-12339 Authenticated Arbitrary File Write Vulnerability in multiple devices — TL-MR6400 v5.3CWE-22 6.9 Medium2026-08-10
CVE-2026-9031 Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6 — Archer A6 v4CWE-20 6.8 Medium2026-08-07
CVE-2026-9030 Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6 — Archer A6 v4CWE-362 6.8 Medium2026-08-07
CVE-2026-15314 Authenticated Denial-of-Service Vulnerability in TP-Link Tapo P110 — P110 v1CWE-120 7.1 High2026-08-04
CVE-2025-15631 Weak Credential Storage in TP-Link Omada Devices — Omada GatewaysCWE-759 5.7 Medium2026-08-03
CVE-2025-15630 Device Provisioning Race Condition in TP-Link Omada Adoption Workflow — Omada GatewaysCWE-362 5.8 Medium2026-08-03
CVE-2025-15629 Weak Session Key Generation in TP-Link Omada Adoption Protocol — Omada GatewaysCWE-331 6.9 Medium2026-08-03
CVE-2025-15628 Hardcoded Certificates in TP-Link Omada Device Communications — Omada GatewaysCWE-798 8.2 High2026-08-03
CVE-2025-15627 Hardcoded Cryptographic Keys in TP-Link Omada Adoption Protocol Authentication — Omada GatewaysCWE-321 6.9 Medium2026-08-03
CVE-2025-15544 Weak Credential Protection During TP-Link Omada Device Adoption — Omada GatewaysCWE-759 6.9 Medium2026-08-03
CVE-2025-9291 Improper Certificate Validation in TP-Link Omada Cloud Communications — Omada GatewaysCWE-295 7.7 High2026-08-03
CVE-2026-9044 Command Injection Vulnerability in OpenVPN of TP-Link Archer AXE75 — AXE75 V1CWE-78 8.5 High2026-07-31
CVE-2026-12935 Unauthenticated Remote Code Execution in TP-Link TL-WR940N RTSP Conntrack Feature — TL-WR940N v6CWE-121 8.7 High2026-07-29
CVE-2026-12001 Hardcoded Credential Vulnerability in Multiple TP-Link Router Models — TL-WR850N v3CWE-798 5.2 Medium2026-07-27
CVE-2026-13230 Information Disclosure Vulnerability in Local Discovery Response in TP-Link Kasa EC70 and EC71 — Kasa EC71 v4CWE-200--2026-07-15
CVE-2026-9770 Hardcoded Cryptographic Key Information Disclosure Vulnerability on TP-Link Kasa EC70 and EC71 — Kasa EC71 v4CWE-321--2026-07-15
CVE-2026-5040 Weak Password Hashing Mechanism in TP-Link Deco M5 — Deco M5 Deco M5 V1CWE-916--2026-07-14
CVE-2026-15429 Privilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800v — Archer VX1800v v1CWE-93--2026-07-14
CVE-2026-15428 OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v — Archer VX1800v v1CWE-78--2026-07-14
CVE-2026-15427 OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v — Archer VX1800v v1CWE-78--2026-07-14
CVE-2026-8699 Stored Cross-Site Scripting (XSS) in TP-Link Archer C5 Web Management Interface — Archer C5 v6.8CWE-79--2026-07-02
CVE-2026-10562 Unauthenticated Open Redirect Vulnerability on TP-Link Archer AX20 Web Interface — Archer AX20 V2.0CWE-601--2026-06-30
CVE-2026-9105 Authenticated Stack-Based Buffer Overflow in TP-Link TL-WR841N Web Interface — TL-WR841N v14CWE-121--2026-06-29
CVE-2026-12760 Denial-of-Service Vulnerability via Malformed IPv4 Fragmentation Handling in TP-Link Tapo C200 — Tapo C200 v3CWE-770--2026-06-24

This page lists every published CVE security advisory associated with TP-Link Systems INC.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.