Vulnerabilidades em TP-Link Systems Inc.

182 resultados
Análise Vexday

Com 121 CVEs catalogadas, os dispositivos TP-Link Systems Inc. apresentam taxa de exploração ativa 1,8× acima da média geral do catálogo CISA KEV, o que indica que vulnerabilidades nesse portfólio têm sido alvo de agentes maliciosos em proporção elevada. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria que facilita execução remota de código e tende a ser explorada com relativa facilidade. O CVE mais crítico em exploração ativa no momento é CVE-2025-9377, com EPSS de 0,1175, e o surgimento de 33 novas CVEs nos últimos 90 dias sinaliza um ritmo recente de descobertas que merece acompanhamento contínuo. Equipes responsáveis por ativos TP-Link devem priorizar a aplicação de patches, especialmente em equipamentos expostos à internet, dada a combinação de exploração ativa confirmada e a prevalência de falhas de injeção de comandos.

CVE-2026-75619MEDIUMRTSP Heap Buffer Overflow Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101EPSS 0.3%CVE-2025-15542MEDIUMDenial of Service (DoS) of VoIP Communication on TP-Link VX800vEPSS 0.3%CVE-2026-15469HIGHHard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800EPSS 0.3%CVE-2026-34122HIGHStack-based Buffer Overflow Leading to Denial of Service in TP-Link Tapo C520WSEPSS 0.3%CVE-2025-9522MEDIUMBlind Server-Side Request Forgery (SSRF) in Omada ControllerEPSS 0.3%CVE-2026-0620MEDIUML2TP over IPSec Encryption Failure on ArcherAXE75EPSS 0.3%CVE-2025-15541MEDIUMAccess to System Files via SFTP on TP-Link VX800vEPSS 0.3%CVE-2026-12001MEDIUMHardcoded Credential Vulnerability in Multiple TP-Link Router ModelsEPSS 0.3%CVE-2026-75118HIGHhttp_gdpr_decrypt Pre-Authentication Stack-Based Buffer OverflowEPSS 0.3%CVE-2026-19683MEDIUMUnencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada GatewaysEPSS 0.3%CVE-2025-14299HIGHImproper Content-Length Validation in HTTPS Requests on Tapo C200EPSS 0.2%CVE-2026-34127MEDIUMStored Cross-Site Scripting (XSS) via Configuration File Import on TP-Link's TL-SG108PEEPSS 0.2%CVE-2025-9293HIGHInsufficient Certificate Validation in Multiple Mobile Applications Allows Man in the Middle InterceptionEPSS 0.2%CVE-2026-75618HIGHRTSP Null Pointer Dereference Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101EPSS 0.2%CVE-2026-18330MEDIUMHardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4EPSS 0.2%CVE-2025-14631HIGHNull Pointer Dereference Vulnerability in Malformed 802.11 Frame of TP-Link Archer BE400EPSS 0.2%CVE-2026-34119HIGHHeap-based Buffer Overflow Vulnerability Leading to Denial-of-Service in TP-Link Tapo C520WSEPSS 0.2%CVE-2026-34120HIGHHeap-based Buffer Overflow Vulnerability Leading to Denial-of-Service in TP-Link Tapo C520WSEPSS 0.2%CVE-2026-15316HIGHDenial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200EPSS 0.2%CVE-2025-30237HIGHAuthentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet DevicesEPSS 0.2%