Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

TP-Link Systems Inc. — Vulnerabilities & Security Advisories 188

Browse all 188 CVE security advisories affecting TP-Link Systems Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TP-Link Systems Inc. operates as a leading manufacturer of consumer networking hardware, primarily producing wireless routers, switches, and smart home devices for residential and small business environments. The company’s firmware and web management interfaces have historically been susceptible to critical vulnerability classes, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These weaknesses often stem from insufficient input validation and hardcoded credentials within embedded web servers, allowing attackers to gain unauthorized administrative access or execute arbitrary commands on affected devices. Notable incidents include the discovery of backdoors in specific router models and widespread exploitation of unpatched RCE vulnerabilities that facilitated botnet recruitment. With over 100 CVEs on record, the firm faces ongoing scrutiny regarding its patch management lifecycle and the security of its IoT ecosystem, necessitating rigorous updates to mitigate persistent risks associated with its extensive global user base.

CVE ID Title CVSS Severity Published
CVE-2025-9522 Blind Server-Side Request Forgery (SSRF) in Omada Controller — Omada Controller CWE-918 7.5AI High AI 2026-01-26
CVE-2025-9521 Password Confirmation Bypass in Omada Controller — Omada Controller CWE-522 7.5AI High AI 2026-01-26
CVE-2025-9520 IDOR Leading to Owner Account Hijacking in Omada Controller — Omada Controller CWE-639 6.5AI Medium AI 2026-01-26
CVE-2025-14756 Authenticated Command Injection Vulnerability in Archer MR600 — Archer MR600 v5.0 CWE-77 8.8AI High AI 2026-01-26
CVE-2025-9290 Authentication Weakness on Omada Controllers, Gateways and Access Points — Omada Software Controller CWE-760 5.9 - 2026-01-22
CVE-2025-9289 Cross-Site Scripting (XSS) on Omada Controllers — Omada Software Controller CWE-79 4.7AI Medium AI 2026-01-22
CVE-2026-0834 Logic Vulnerability on TP-Link Archer C20, Archer AX53 and TL-WR841N v13 — Archer C20 v6.0, Archer AX53 v1.0 CWE-290 8.8AI High AI 2026-01-21
CVE-2026-0629 Authentication Bypass in Password Recovery Feature via Local Web App on Multiple VIGI Cameras — VIGI InSight Sx45 Series (S245/S345/S445) CWE-287 8.8 - 2026-01-16
CVE-2025-9014 Null Pointer Dereference Vulnerability on TL-WR841N — TL-WR841N v14 CWE-20 7.5AI High AI 2026-01-15
CVE-2025-15035 Arbitrary File Deletion Vulnerability in TP-Link Archer AXE75 — Archer AXE75 v1.6 CWE-20 7.3 - 2026-01-09
CVE-2025-14631 Null Pointer Dereference Vulnerability in Malformed 802.11 Frame of TP-Link Archer BE400 — Archer BE400 CWE-476 6.5 - 2026-01-07
CVE-2025-14175 Weak Algorithm Support in SSH Server on TL-WR820N — TL-WR820N v2.8 CWE-327 6.5 - 2025-12-29
CVE-2025-14300 Unauthenticated Access to connectAP API Endpoint on Tapo C100, C200 & C425 — Tapo C200 CWE-306 8.7 High 2025-12-20
CVE-2025-14299 Improper Content-Length Validation in HTTPS Requests on Tapo C200 — Tapo C200 V3 CWE-770 5.7AI Medium AI 2025-12-20
CVE-2025-8065 Remote Code Execution via Stack-based Buffer Overflow in ONVIF SOAP Parser in TP-Link Tapo C200 and C520WS — Tapo C200 V3 CWE-121 6.5AI Medium AI 2025-12-20
CVE-2025-14739 Uninitialized Pointer Vulnerability in TP-Link WR940N and WR941ND — WR940N and WR941ND CWE-824 8.4AI High AI 2025-12-18
CVE-2025-14738 Configuration Disclosure Vulnerability in TP-Link WA850RE — WA850RE CWE-287 7.5AI High AI 2025-12-18
CVE-2025-14737 Command Injection Vulnerability in TP-Link WA850RE — WA850RE CWE-78 8.0AI High AI 2025-12-18
CVE-2025-14553 Password Hash Leak Could Lead to Unauthorized Access on Tapo App via Local Network — TP-Link Tapo App CWE-200 7.3AI High AI 2025-12-16
CVE-2025-7851 Unauthorized root access via debug functionality — Omada gateways 8.4AI High AI 2025-10-21
CVE-2025-7850 Authenticated OS command execution — Omada gateways CWE-78 7.2AI High AI 2025-10-21
CVE-2025-6542 OS command injection in multiple parameters — Omada gateways CWE-78 9.8AI Critical AI 2025-10-21
CVE-2025-6541 OS command injection using information obtained from the web management interface — Omada gateways CWE-78 7.2AI High AI 2025-10-21
CVE-2025-10991 Root Access via UART — Tapo D230S1 V1.20 6.8AI Medium AI 2025-09-30
CVE-2025-9961 Authenticated RCE by CWMP binary — AX10 V1/V1.2/V2/V2.6/V3/V3.6 CWE-120 7.5AI High AI 2025-09-06
CVE-2025-9377 Authenticated RCE via Parental Control command injection — Archer C7(EU) V2 CWE-78 8.8 - 2025-08-29
CVE-2025-8627 Unauthenticated Protocol Commands on TP-Link KP303 — TP-Link KP303 (US) Smartplug 8.1AI High AI 2025-08-25
CVE-2025-53715 TP-Link TL-WR841N Wan6to4TunnelCfgRpm.htm buffer overflow — TL-WR841N V11 CWE-119 7.5AI High AI 2025-07-29
CVE-2025-53714 TP-Link TL-WR841N WzdWlanSiteSurveyRpm_AP.htm buffer overflow — TL-WR841N V11 CWE-119 7.5AI High AI 2025-07-29
CVE-2025-53713 TP-Link TL-WR841N WlanNetworkRpm_APC.htm buffer overflow — TL-WR841N V11 CWE-120 7.5AI High AI 2025-07-29

This page lists every published CVE security advisory associated with TP-Link Systems Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.