Skip to main content

Vendor archive

tp-link CVEs

Beta · best-effort

522 CVEs tagged to vendor tp-link94 Critical, 295 High, 130 Medium, 3 Low, 0 Unrated.

CVE-2020-28347

Published Nov 8, 2020

tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this issue exists because of an in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-24363

Published Aug 31, 2020

TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The att…

CVSS 8.8 · High
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-13224

Published Jun 17, 2020

TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, N…

CVSS 8.8 · High

CVE-2020-12109

Published May 4, 2020

Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 b…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2020-12475

Published May 4, 2020

TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.portal.PortalController.getAdvertiseFile in /opt/tplink/EAPC…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12110

Published May 4, 2020

Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2020-10231

Published Apr 1, 2020

TP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 through 1.3.0_Build_171205, NC250 through 1.3.0_Build_171205, N…

CVSS 7.5 · High

CVE-2020-10888

Published Mar 25, 2020

This vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not requi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10887

Published Mar 25, 2020

This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vuln…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10886

Published Mar 25, 2020

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not requ…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 351-375 of 522 CVEsPage 15 of 21