Vulnerabilidades em TP-Link Systems Inc.

182 resultados
Análise Vexday

Com 121 CVEs catalogadas, os dispositivos TP-Link Systems Inc. apresentam taxa de exploração ativa 1,8× acima da média geral do catálogo CISA KEV, o que indica que vulnerabilidades nesse portfólio têm sido alvo de agentes maliciosos em proporção elevada. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria que facilita execução remota de código e tende a ser explorada com relativa facilidade. O CVE mais crítico em exploração ativa no momento é CVE-2025-9377, com EPSS de 0,1175, e o surgimento de 33 novas CVEs nos últimos 90 dias sinaliza um ritmo recente de descobertas que merece acompanhamento contínuo. Equipes responsáveis por ativos TP-Link devem priorizar a aplicação de patches, especialmente em equipamentos expostos à internet, dada a combinação de exploração ativa confirmada e a prevalência de falhas de injeção de comandos.

CVE-2025-9290MEDIUMAuthentication Weakness on Omada Controllers, Gateways and Access PointsEPSS 0.2%CVE-2025-15628HIGHHardcoded Certificates in TP-Link Omada Device CommunicationsEPSS 0.2%CVE-2025-7375MEDIUMUnauthenticated Denial-of-Service Vulnerability in Omada EAP610EPSS 0.2%CVE-2026-5511MEDIUMInformation Disclosure via Diagnostic Interface Due to Improper Input Validation on TP-Link's Archer AX72EPSS 0.2%CVE-2026-22220MEDIUMImproper Input Validation Leading to DoS on TP-Link Archer BE230EPSS 0.2%CVE-2025-14739MEDIUMUninitialized Pointer Vulnerability in TP-Link WR940N and WR941NDEPSS 0.2%CVE-2026-85384HIGHAuthenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration ImportEPSS 0.2%CVE-2026-8714HIGHDenial-of-Service Vulnerability in RTSP Input Handling on TP-Link's Tapo C520WSEPSS 0.2%CVE-2025-15544MEDIUMWeak Credential Protection During TP-Link Omada Device AdoptionEPSS 0.2%CVE-2025-9289MEDIUMCross-Site Scripting (XSS) on Omada ControllersEPSS 0.2%CVE-2025-15630MEDIUMDevice Provisioning Race Condition in TP-Link Omada Adoption WorkflowEPSS 0.2%CVE-2026-9033MEDIUMUnauthenticated Captive Portal Session Termination and Forced Logout in Omada GatewaysEPSS 0.2%CVE-2025-15543MEDIUMRead-Only Root Access via USB Storage Device in TP-Link VX800vEPSS 0.2%CVE-2025-14553HIGHPassword Hash Leak Could Lead to Unauthorized Access on Tapo App via Local NetworkEPSS 0.2%CVE-2025-15557HIGHImproper Certificate Validation in TP-Link Tapo H100 and P100 Allows Man-in-the-Middle AttackEPSS 0.2%CVE-2026-17250HIGHAuthenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update HandlingEPSS 0.2%CVE-2025-15629MEDIUMWeak Session Key Generation in TP-Link Omada Adoption ProtocolEPSS 0.2%CVE-2026-6239MEDIUMAuthenticated Stack-based Buffer Overflow in ONVIF CreateUsers Service in TP-Link Tao C520WSEPSS 0.2%CVE-2026-6240MEDIUMAuthenticated Stack-based Buffer Overflow in ONVIF DeleteUsers Service on TP-Link Tapo C520WSEPSS 0.2%CVE-2025-30240MEDIUMArbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP-Link Aginet DevicesEPSS 0.2%