Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

TP-Link Systems Inc. — Vulnerabilities & Security Advisories 188

Browse all 188 CVE security advisories affecting TP-Link Systems Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TP-Link Systems Inc. operates as a leading manufacturer of consumer networking hardware, primarily producing wireless routers, switches, and smart home devices for residential and small business environments. The company’s firmware and web management interfaces have historically been susceptible to critical vulnerability classes, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These weaknesses often stem from insufficient input validation and hardcoded credentials within embedded web servers, allowing attackers to gain unauthorized administrative access or execute arbitrary commands on affected devices. Notable incidents include the discovery of backdoors in specific router models and widespread exploitation of unpatched RCE vulnerabilities that facilitated botnet recruitment. With over 100 CVEs on record, the firm faces ongoing scrutiny regarding its patch management lifecycle and the security of its IoT ecosystem, necessitating rigorous updates to mitigate persistent risks associated with its extensive global user base.

CVE ID Title CVSS Severity Published
CVE-2025-62405 Heap-based Buffer Overflow Vulnerability in TP-Link Archer AX53 — Archer AX53 v1.0 CWE-122 8.0AI High AI 2026-02-03
CVE-2025-62404 Heap-based Buffer Overflow Vulnerability in TP-Link Archer AX53 — Archer AX53 v1.0 CWE-122 8.0AI High AI 2026-02-03
CVE-2025-61983 Heap-based Buffer Overflow Vulnerability in TP-Link Archer AX53 — Archer AX53 v1.0 CWE-122 8.0AI High AI 2026-02-03
CVE-2025-61944 Heap-based Buffer Overflow Vulnerability in TP-Link Archer AX53 — Archer AX53 v1.0 CWE-122 8.0AI High AI 2026-02-03
CVE-2025-59487 Heap-based Buffer Overflow Vulnerability in TP-Link Archer AX53 — Archer AX53 v1.0 CWE-122 8.0AI High AI 2026-02-03
CVE-2025-59482 Heap-based Buffer Overflow Vulnerability in TP-Link Archer AX53 — Archer AX53 v1.0 CWE-122 8.0AI High AI 2026-02-03
CVE-2025-58455 Heap-based Buffer Overflow Vulnerability in TP-Link Archer AX53 — Archer AX53 v1.0 CWE-122 8.0AI High AI 2026-02-03
CVE-2025-58077 Heap-based Buffer Overflow Vulnerability in TP-Link Archer AX53 — Archer AX53 v1.0 CWE-122 8.0AI High AI 2026-02-03
CVE-2026-0620 L2TP over IPSec Encryption Failure on ArcherAXE75 — AXE75 CWE-693 7.5AI High AI 2026-02-03
CVE-2026-22228 Improper Input Validation Leading to DoS on TP-Link Archer BE230 — Archer BE230 v1.2 CWE-400 4.4AI Medium AI 2026-02-03
CVE-2026-22220 Improper Input Validation Leading to DoS on TP-Link Archer BE230 — Archer BE230 v1.2 CWE-20 4.5AI Medium AI 2026-02-03
CVE-2026-22229 Command Injection Vulnerability on TP-Link Archer BE230 v1.2 and Deco BE25 v1.0 — Archer BE230 v1.2 CWE-78 7.7AI High AI 2026-02-02
CVE-2026-22227 Command Injection Vulnerability on TP-Link Archer BE230 v1.2 — Archer BE230 v1.2 CWE-78 8.4AI High AI 2026-02-02
CVE-2026-22226 Command Injection Vulnerability on TP-Link Archer BE230 and AX73 — Archer BE230 v1.2 CWE-78 8.4AI High AI 2026-02-02
CVE-2026-22225 Command Injection Vulnerability on TP-Link Archer BE230 v1.2 and AXE75 v1.0 — Archer BE230 v1.2 CWE-78 8.4AI High AI 2026-02-02
CVE-2026-22224 Command Injection Vulnerability on TP-Link Archer BE230 v1.2 — Archer BE230 v1.2 CWE-78 8.4AI High AI 2026-02-02
CVE-2026-22222 Command Injection Vulnerability on TP-Link Archer BE230 v1.2 — Archer BE230 v1.2 CWE-78 9.0AI Critical AI 2026-02-02
CVE-2026-0631 Authenticated Command Injection Vulnerability in Surfshark VPN Login in Archer BE230, BE3600 and AXE75 — Archer BE230 v1.2 CWE-78 8.5 High 2026-02-02
CVE-2026-0630 Command Injection Vulnerability on TP-Link Archer BE230 v1.2 and AXE75 v1.0 — Archer BE230 v1.2 CWE-78 8.0AI High AI 2026-02-02
CVE-2026-22221 Command Injection Vulnerability on TP-Link Archer BE230 v1.2 and BE3600 v1 — Archer BE230 v1.2 CWE-78 8.5 High 2026-02-02
CVE-2026-1457 Authenticated RCE Vulnerability Due to Buffer Overflow on TP-Link VIGI C385 — VIGI C485 V1 CWE-121 8.8AI High AI 2026-01-29
CVE-2025-15548 Missing Application-Layer Encryption in Web Interface Endpoints on TP-Link VX800v — VX800v v1.0 CWE-311 6.5AI Medium AI 2026-01-29
CVE-2025-15543 Read-Only Root Access via USB Storage Device in TP-Link VX800v — VX800v v1.0 CWE-59 4.6AI Medium AI 2026-01-29
CVE-2025-15542 Denial of Service (DoS) of VoIP Communication on TP-Link VX800v — VX800v v1.0 CWE-754 7.5AI High AI 2026-01-29
CVE-2025-15541 Access to System Files via SFTP on TP-Link VX800v — VX800v v1.0 CWE-59 5.7AI Medium AI 2026-01-29
CVE-2025-13399 Insecure Encryption in Communication with the Web Interface on TP-Link VX800v — VX800v v1.0 CWE-331 6.8AI Medium AI 2026-01-29
CVE-2025-15545 Insufficient Backup File Upload Input Validation on TP-Link Archer RE605X — Archer RE605X CWE-20 7.8AI High AI 2026-01-29
CVE-2026-1315 Unauthenticated Denial of Service via Firmware Update Endpoint on TP-Link Tapo C220 & C520WS — Tapo C220 v1 CWE-20 6.5AI Medium AI 2026-01-27
CVE-2026-0919 Unauthenticated Denial of Service via Oversized URL in HTTP Parser on TP-Link Tapo C210, C220 & C520WS — Tapo C220 v1 CWE-20 7.5AI High AI 2026-01-27
CVE-2026-0918 Null Pointer Dereference in Tapo SmartCam HTTP Service on TP-Link Tapo C220 & C520WS — Tapo C220 v1 CWE-476 7.5AI High AI 2026-01-27

This page lists every published CVE security advisory associated with TP-Link Systems Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.