Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

TP-Link Systems Inc. — Vulnerabilities & Security Advisories 181

Browse all 181 CVE security advisories affecting TP-Link Systems Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TP-Link Systems Inc. operates as a leading manufacturer of consumer networking hardware, primarily producing wireless routers, switches, and smart home devices for residential and small business environments. The company’s firmware and web management interfaces have historically been susceptible to critical vulnerability classes, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These weaknesses often stem from insufficient input validation and hardcoded credentials within embedded web servers, allowing attackers to gain unauthorized administrative access or execute arbitrary commands on affected devices. Notable incidents include the discovery of backdoors in specific router models and widespread exploitation of unpatched RCE vulnerabilities that facilitated botnet recruitment. With over 100 CVEs on record, the firm faces ongoing scrutiny regarding its patch management lifecycle and the security of its IoT ecosystem, necessitating rigorous updates to mitigate persistent risks associated with its extensive global user base.

CVE ID Title CVSS Severity Published
CVE-2026-84941 Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read — Omada Software Controller (Windows) CWE-611 6.9 Medium 2026-09-10
CVE-2026-17176 OS command injection Vulnerability in Deco BE11000 — Deco BE11000 V2 CWE-78 7.7 High 2026-09-10
CVE-2026-76652 Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600 — TL-MR6400 v8 CWE-22 4.8 Medium 2026-09-10
CVE-2026-76653 Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR600 — TL-MR6400 v8 CWE-126 5.3 Medium 2026-09-10
CVE-2026-85384 Authenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration Import — RE210 AC750 CWE-121 8.5 High 2026-09-08
CVE-2026-18167 Stack-based buffer overflow in TP-Link Archer AX55 v4 — Archer AX55 v4 CWE-121 7.7 High 2026-09-03
CVE-2026-18330 Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4 — Archer AX55 v4 CWE-321 6.1 Medium 2026-09-03
CVE-2026-75118 http_gdpr_decrypt Pre-Authentication Stack-Based Buffer Overflow — TL-MR100 v3.20 CWE-121 8.7 High 2026-08-28
CVE-2026-76784 Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices — HS103P3 / HS103P4 v5 CWE-325 8.7 High 2026-08-26
CVE-2026-78541 Command Injection in Parent Control of TP-Link Archer BE3600 v1 — Archer BE3600 v1 CWE-78 8.5 High 2026-08-24
CVE-2026-16348 Command Injection Vulnerability in VPN connection of Archer BE800 — Archer BE800 v1 CWE-78 8.5 High 2026-08-24
CVE-2026-9254 Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices — Archer BE800 V1 CWE-78 8.7 High 2026-08-24
CVE-2026-15469 Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800 — Deco XE75 v3 / XE5300 v3.6/ WE10800 v3.6 CWE-321 7.7 High 2026-08-24
CVE-2026-17252 Unauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based Out-of-Bounds Write Vulnerability in TL-MR6400 Web Management Interface — TL-MR6400 v7.0 CWE-787 7.1 High 2026-08-21
CVE-2026-17251 Unauthenticated Denial of Service via Null Pointer Dereference in HTTP Request Parsing — TL-MR6400 v7.0 CWE-476 7.1 High 2026-08-21
CVE-2026-17250 Authenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update Handling — TL-MR6400 v7.0 CWE-121 8.5 High 2026-08-21
CVE-2026-19683 Unencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada Gateways — ER7212PC v2 CWE-319 6.3 Medium 2026-08-20
CVE-2026-19586 Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways — ER7212PC v2 CWE-78 9.3 Critical 2026-08-20
CVE-2026-9033 Unauthenticated Captive Portal Session Termination and Forced Logout in Omada Gateways — ER7212PC v2 CWE-306 6.0 Medium 2026-08-20
CVE-2026-8619 Unauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR150, TL-MR6400 and Archer MR600 — TL-MR100 v3.2 CWE-476 7.1 High 2026-08-19
CVE-2026-75616 Command Injection in Router Web Management Interface — Archer C20 v6 CWE-78 8.5 High 2026-08-19
CVE-2026-75619 RTSP Heap Buffer Overflow Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101 — Tapo C100 v5 CWE-122 6.9 Medium 2026-08-19
CVE-2026-75618 RTSP Null Pointer Dereference Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101 — Tapo C100 v5 CWE-476 7.1 High 2026-08-19
CVE-2026-15316 Denial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200 — Tapo C200 v5 CWE-20 7.1 High 2026-08-18
CVE-2026-15315 Unauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link Tapo C120 and C200 — Tapo C200 v5 CWE-287 8.7 High 2026-08-18
CVE-2026-15141 Referer Validation Bypass in TL-WR820N Web Management Interface — TL-WR820N v2 CWE-346 5.3 Medium 2026-08-12
CVE-2025-30241 OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices — HB810(US2) V1.0/1.6/2.0/2.6 CWE-78 8.6 High 2026-08-10
CVE-2025-30240 Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP-Link Aginet Devices — HB810(US2) V1.0/1.6/2.0/2.6 CWE-59 5.1 Medium 2026-08-10
CVE-2025-30239 Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet Devices — HB810(US2) V1.0/1.6/2.0/2.6 CWE-321 8.5 High 2026-08-10
CVE-2025-30238 Privilege Escalation via Improper Authorization in User Management in multiple TP-Link Aginet Devices — HB810(US2) V1.0/1.6/2.0/2.6 CWE-863 8.6 High 2026-08-10

This page lists every published CVE security advisory associated with TP-Link Systems Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.