Vulnerabilities in TP-Link

112 results
Vexday analysis

Com 74 CVEs catalogadas, os dispositivos TP-Link apresentam uma taxa de exploração ativa 3,0× acima da média geral do catálogo CISA KEV, sinal de que vulnerabilidades nessa plataforma atraem atenção real de agentes de ameaça, não apenas pesquisadores. O tipo de falha mais frequente é CWE-121 (stack-based buffer overflow), classe de vulnerabilidade que historicamente permite execução remota de código e eleva o risco em equipamentos de borda de rede. Entre as 8 CVEs críticas e 7 com prova de conceito pública, destaca-se CVE-2023-50224, atualmente confirmada em exploração ativa e com EPSS de 0,1745, enquanto o maior EPSS observado no portfólio chega a 0,7284 — indicando que ao menos uma falha é considerada de alta probabilidade de exploração iminente. Equipes de segurança que operam dispositivos TP-Link devem priorizar a aplicação de patches nas CVEs críticas com PoC disponível e monitorar continuamente o status KEV dado o histórico de exploração acima da média.

CVE-2021-4045CRITICALTP-LINK Tapo C200 remote code execution vulnerabilityEPSS 72.4%CVE-2020-10882HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: EPSS 41.4%CVE-2020-10884HIGHThis vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190EPSS 24.7%CVE-2023-50224MEDIUMTP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure VulnerabilityEPSS 17.4%KEVCVE-2019-17147HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication EPSS 13.7%CVE-2023-49074HIGHA denial of service vulnerability exists in the TDDP functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.EPSS 13.5%CVE-2018-5393TP-Link EAP Controller versions 2.5.3 and earlier lack RMI authenticationEPSS 12.9%CVE-2020-10881CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1EPSS 10.9%CVE-2024-12342HIGHTP-Link VN020 F3v(T) Incomplete SOAP Request WANIPConnection denial of serviceEPSS 8.9%CVE-2021-35004HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link TL-WA1201 1.0.1 Build 20200709 relEPSS 7.7%CVE-2021-35003CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer C90 1.0.6 Build 20200114 reEPSS 7.7%CVE-2020-10885HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1EPSS 7.2%CVE-2021-27246HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 AC1750 1.0.15 EPSS 6.6%CVE-2020-10883MEDIUMThis vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 EPSS 5.9%CVE-2020-10886HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1EPSS 5.5%CVE-2024-11237HIGHTP-Link VN020 F3v(T) DHCP DISCOVER Packet Parser TP-Thumper stack-based overflowEPSS 5.2%CVE-2024-12343HIGHTP-Link VN020 F3v(T) SOAP Request WANIPConnection buffer overflowEPSS 4.7%CVE-2020-10887HIGHThis vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. AuthenticatiEPSS 4.1%CVE-2023-47617HIGHA post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN RouteEPSS 3.4%CVE-2023-47209HIGHA post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.EPSS 3.4%