Vulnerabilities in TP-Link Systems Inc.

182 results
Vexday analysis

Com 121 CVEs catalogadas, os dispositivos TP-Link Systems Inc. apresentam taxa de exploração ativa 1,8× acima da média geral do catálogo CISA KEV, o que indica que vulnerabilidades nesse portfólio têm sido alvo de agentes maliciosos em proporção elevada. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria que facilita execução remota de código e tende a ser explorada com relativa facilidade. O CVE mais crítico em exploração ativa no momento é CVE-2025-9377, com EPSS de 0,1175, e o surgimento de 33 novas CVEs nos últimos 90 dias sinaliza um ritmo recente de descobertas que merece acompanhamento contínuo. Equipes responsáveis por ativos TP-Link devem priorizar a aplicação de patches, especialmente em equipamentos expostos à internet, dada a combinação de exploração ativa confirmada e a prevalência de falhas de injeção de comandos.

CVE-2025-53713MEDIUMTP-Link TL-WR841N WlanNetworkRpm_APC.htm buffer overflowEPSS 0.3%CVE-2025-53712MEDIUMTP-Link TL-WR841N WlanNetworkRpm_AP.htm buffer overflowEPSS 0.3%CVE-2025-53715MEDIUMTP-Link TL-WR841N Wan6to4TunnelCfgRpm.htm buffer overflowEPSS 0.3%CVE-2025-53714MEDIUMTP-Link TL-WR841N WzdWlanSiteSurveyRpm_AP.htm buffer overflowEPSS 0.3%CVE-2025-53711MEDIUMTP-Link TL-WR841N, TL-WR842ND and TL-WR949N WlanNetworkRpm.htm buffer overflowEPSS 0.3%CVE-2025-15035MEDIUMArbitrary File Deletion Vulnerability in TP-Link Archer AXE75EPSS 0.3%CVE-2026-1871HIGHAuthenticated Stack-based Buffer Overflow in RTSP Authentication of Tapo C200EPSS 0.3%CVE-2026-15315HIGHUnauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link Tapo C120 and C200EPSS 0.3%CVE-2025-15631MEDIUMWeak Credential Storage in TP-Link Omada DevicesEPSS 0.3%CVE-2026-1571MEDIUMReflected XSS Vulnerability on TP-Link Archer C60EPSS 0.3%CVE-2025-14175MEDIUMWeak Algorithm Support in SSH Server on TL-WR820NEPSS 0.3%CVE-2026-17250HIGHAuthenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update HandlingEPSS 0.3%CVE-2025-15606HIGHDenial of Service (DoS) in HTTPD Input Handling on TP-Link TD-W8961NEPSS 0.3%CVE-2026-0654HIGHCommand injection on TP-Link Deco BE25EPSS 0.3%CVE-2025-9522MEDIUMBlind Server-Side Request Forgery (SSRF) in Omada ControllerEPSS 0.3%CVE-2026-8699HIGHStored Cross-Site Scripting (XSS) in TP-Link Archer C5 Web Management InterfaceEPSS 0.3%CVE-2025-6982MEDIUMHardcoded DES Decryption Keys in TP-Link Archer C50 V3/V4/V5 and C20 V5EPSS 0.3%CVE-2026-9033MEDIUMUnauthenticated Captive Portal Session Termination and Forced Logout in Omada GatewaysEPSS 0.3%CVE-2026-6239MEDIUMAuthenticated Stack-based Buffer Overflow in ONVIF CreateUsers Service in TP-Link Tao C520WSEPSS 0.3%CVE-2026-6240MEDIUMAuthenticated Stack-based Buffer Overflow in ONVIF DeleteUsers Service on TP-Link Tapo C520WSEPSS 0.3%