Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

TP-Link Systems Inc. — Vulnerabilities & Security Advisories 158

Browse all 158 CVE security advisories affecting TP-Link Systems Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TP-Link Systems Inc. operates as a leading manufacturer of consumer networking hardware, primarily producing wireless routers, switches, and smart home devices for residential and small business environments. The company’s firmware and web management interfaces have historically been susceptible to critical vulnerability classes, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These weaknesses often stem from insufficient input validation and hardcoded credentials within embedded web servers, allowing attackers to gain unauthorized administrative access or execute arbitrary commands on affected devices. Notable incidents include the discovery of backdoors in specific router models and widespread exploitation of unpatched RCE vulnerabilities that facilitated botnet recruitment. With over 100 CVEs on record, the firm faces ongoing scrutiny regarding its patch management lifecycle and the security of its IoT ecosystem, necessitating rigorous updates to mitigate persistent risks associated with its extensive global user base.

CVE IDTitleCVSSSeverityPublished
CVE-2026-34121 Authentication Bypass in DS Configuration Service via HTTP Request Parsing Differential of TP-Link Tapo C520WS — Tapo C520WS v2.6CWE-287 5.3AIMediumAI2026-04-02
CVE-2026-34120 Heap-based Buffer Overflow Vulnerability Leading to Denial-of-Service in TP-Link Tapo C520WS — Tapo C520WS v2.6CWE-122 6.5AIMediumAI2026-04-02
CVE-2026-34119 Heap-based Buffer Overflow Vulnerability Leading to Denial-of-Service in TP-Link Tapo C520WS — Tapo C520WS v2.6CWE-122 6.5AIMediumAI2026-04-02
CVE-2026-34118 Heap-based Buffer Overflow Vulnerability Leading to Denial-of-Service in TP-Link Tapo C520WS — Tapo C520WS v2.6CWE-122 6.5AIMediumAI2026-04-02
CVE-2026-4346 Cleartext Storage of Administrative and Wi-Fi Credentials via Accessible Serial Interface in TP Link's TL-WR850N — TL-WR850N v3CWE-312 6.8AIMediumAI2026-03-26
CVE-2026-3622 Denial-of-Service Vulnerability in UPnP Component of TP Link's TL-WR841N — TL-WR841N v14CWE-125 7.5AIHighAI2026-03-26
CVE-2025-15606 Denial of Service (DoS) in HTTPD Input Handling on TP-Link TD-W8961N — TD-W8961N v4.0CWE-20 7.5 -2026-03-23
CVE-2025-15605 Hardcoded Cryptographic Key in Configuration Encryption Mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 — Archer NX600 v3.0CWE-321 7.1 -2026-03-23
CVE-2025-15519 Command Injection in Modem Management CLI on TP-Link Archer NX200, NX210, NX500 and NX600 — Archer NX600 v3.0CWE-78 6.7 -2026-03-23
CVE-2025-15518 Command Injection in Wireless Control CLI on TP-Link Archer NX200, NX210, NX500 and NX600 — Archer NX600 v3.0CWE-78 6.7 -2026-03-23
CVE-2025-15517 Authorization Bypass in HTTP Server Endpoints on TP-Link Archer NX200, NX210, NX500 and NX600 — Archer NX600 v3.0CWE-306 9.8 -2026-03-23
CVE-2025-15608 Buffer Overflow in Network Probe Handling Function of TP-Link Archer AX53 + Archer AX55 — AX53 v1CWE-121 7.7 High2026-03-20
CVE-2025-15607 Authenticated Command Injection in mcsd Service of TP-Link Archer AX53 — AX53 v1CWE-77 8.8 -2026-03-20
CVE-2026-3227 Authenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N — TL-WR802N v4CWE-78 8.8AIHighAI2026-03-13
CVE-2026-1668 Input Validation Vulnerability on Multiple Omada Switches — SG2008P 3.2xCWE-20 9.8 -2026-03-13
CVE-2026-3841 Command Injection Vulnerability in Telnet CLI on TP-Link TL-MR6400 — TL-MR6400 v5.3CWE-78 7.2AIHighAI2026-03-12
CVE-2025-15568 Command Injection Vulnerability on TP-Link Archer AXE75 — Archer AXE75 v1.6/v1.0CWE-78 8.0AIHighAI2026-03-09
CVE-2025-7375 Unauthenticated Denial-of-Service Vulnerability in Omada EAP610 — EAP610 v3CWE-20 6.5 -2026-03-05
CVE-2026-0654 Command injection on TP-Link Deco BE25 — Deco BE25 v1.0CWE-78 8.0AIHighAI2026-03-02
CVE-2026-0655 Path Traversal on TP-Link Deco BE25 — Deco BE25 v1.0CWE-22 7.3AIHighAI2026-03-02
CVE-2025-9293 Insufficient Certificate Validation in Multiple Mobile Applications Allows Man in the Middle Interception — Tapo AppCWE-295 6.8AIMediumAI2026-02-13
CVE-2025-9292 Permissive Web Security Policy Allows Cross-Origin Access Control Bypass on Omada Cloud Controllers — Omada Cloud ControllerCWE-942 7.5AIHighAI2026-02-13
CVE-2026-1571 Reflected XSS Vulnerability on TP-Link Archer C60 — Archer C60 v3CWE-79 6.1AIMediumAI2026-02-11
CVE-2026-0651 Path Traversal on TP-Link Tapo D235, C211, C520WS and C260 via Local https — Tapo C260 v1CWE-22 6.9 Medium2026-02-10
CVE-2026-0652 Remote Code Execution on TP-Link Tapo C260 by Guest User — Tapo C260 v1CWE-78 8.8AIHighAI2026-02-10
CVE-2026-0653 Insecure Access Control on TP-Link Tapo D235 and C260 — Tapo C260 v1CWE-284 7.2 High2026-02-10
CVE-2025-15557 Improper Certificate Validation in TP-Link Tapo H100 and P100 Allows Man-in-the-Middle Attack — Tapo H100 v1CWE-295 7.5AIHighAI2026-02-05
CVE-2025-15551 LAN Code Execution on TP-Link Archer MR200, Archer C20, TL-WR850N and TL-WR845N — Archer MR200 v5.2CWE-95 8.1AIHighAI2026-02-05
CVE-2025-62673 Heap-based Buffer Overflow Vulnerability in TP-Link Archer AX53 — Archer AX53 v1.0CWE-122 8.8AIHighAI2026-02-03
CVE-2025-62501 SSH Hostkey Misconfiguration Vulnerability in TP-Link Archer AX53 — Archer AX53 v1.0CWE-322 8.1AIHighAI2026-02-03

This page lists every published CVE security advisory associated with TP-Link Systems Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.