Browse all 188 CVE security advisories affecting TP-Link Systems Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.
TP-Link Systems Inc. operates as a leading manufacturer of consumer networking hardware, primarily producing wireless routers, switches, and smart home devices for residential and small business environments. The company’s firmware and web management interfaces have historically been susceptible to critical vulnerability classes, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These weaknesses often stem from insufficient input validation and hardcoded credentials within embedded web servers, allowing attackers to gain unauthorized administrative access or execute arbitrary commands on affected devices. Notable incidents include the discovery of backdoors in specific router models and widespread exploitation of unpatched RCE vulnerabilities that facilitated botnet recruitment. With over 100 CVEs on record, the firm faces ongoing scrutiny regarding its patch management lifecycle and the security of its IoT ecosystem, necessitating rigorous updates to mitigate persistent risks associated with its extensive global user base.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-30241 | OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices — HB810(US2) V1.0/1.6/2.0/2.6 CWE-78 | 8.6 | High | 2026-08-10 |
| CVE-2025-30240 | Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP-Link Aginet Devices — HB810(US2) V1.0/1.6/2.0/2.6 CWE-59 | 5.1 | Medium | 2026-08-10 |
| CVE-2025-30239 | Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet Devices — HB810(US2) V1.0/1.6/2.0/2.6 CWE-321 | 8.5 | High | 2026-08-10 |
| CVE-2025-30238 | Privilege Escalation via Improper Authorization in User Management in multiple TP-Link Aginet Devices — HB810(US2) V1.0/1.6/2.0/2.6 CWE-863 | 8.6 | High | 2026-08-10 |
| CVE-2025-30237 | Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet Devices — HB810(US2) V1.0/1.6/2.0/2.6 CWE-862 | 8.7 | High | 2026-08-10 |
This page lists every published CVE security advisory associated with TP-Link Systems Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.