Vulnerabilidades em TP-Link Systems Inc.

182 resultados
Análise Vexday

Com 121 CVEs catalogadas, os dispositivos TP-Link Systems Inc. apresentam taxa de exploração ativa 1,8× acima da média geral do catálogo CISA KEV, o que indica que vulnerabilidades nesse portfólio têm sido alvo de agentes maliciosos em proporção elevada. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria que facilita execução remota de código e tende a ser explorada com relativa facilidade. O CVE mais crítico em exploração ativa no momento é CVE-2025-9377, com EPSS de 0,1175, e o surgimento de 33 novas CVEs nos últimos 90 dias sinaliza um ritmo recente de descobertas que merece acompanhamento contínuo. Equipes responsáveis por ativos TP-Link devem priorizar a aplicação de patches, especialmente em equipamentos expostos à internet, dada a combinação de exploração ativa confirmada e a prevalência de falhas de injeção de comandos.

CVE-2025-15631MEDIUMWeak Credential Storage in TP-Link Omada DevicesEPSS 0.2%CVE-2026-6242MEDIUMAuthenticated Format String Vulnerability in ONVIF Subscribe Service on TP-Link Tapo C520WSEPSS 0.2%CVE-2025-10991HIGHRoot Access via UARTEPSS 0.2%CVE-2026-17252HIGHUnauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based Out-of-Bounds Write Vulnerability in TL-MR6400 Web Management InterfaceEPSS 0.2%CVE-2026-6241MEDIUMAuthenticated Format String Vulnerability in ONVIF AddScopes Method on TP-Link Tapo C520WSEPSS 0.2%CVE-2026-9031MEDIUMAuthenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6EPSS 0.2%CVE-2025-13399HIGHInsecure Encryption in Communication with the Web Interface on TP-Link VX800vEPSS 0.2%CVE-2026-34123HIGHWhitelist Validation Bypass in TP-Link Tapo C520WSEPSS 0.2%CVE-2026-76784HIGHInsufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home DevicesEPSS 0.1%CVE-2025-4975MEDIUMTapo privilege escalation on shared devices using notificationsEPSS 0.1%CVE-2025-30239HIGHSensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet DevicesEPSS 0.1%CVE-2025-30238HIGHPrivilege Escalation via Improper Authorization in User Management in multiple TP-Link Aginet DevicesEPSS 0.1%CVE-2025-15605HIGHHardcoded Cryptographic Key in Configuration Encryption Mechanism on TP-Link Archer NX200, NX210, NX500 and NX600EPSS 0.1%CVE-2025-9291HIGHImproper Certificate Validation in TP-Link Omada Cloud CommunicationsEPSS 0.1%CVE-2026-5039MEDIUMPredictable Default Cryptographic Key Used for DES Encryption in TP-Link TL-WL841NEPSS 0.1%CVE-2026-9030MEDIUMAuthenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6EPSS 0.1%CVE-2026-4346MEDIUMCleartext Storage of Administrative and Wi-Fi Credentials via Accessible Serial Interface in TP Link's TL-WR850NEPSS 0.1%CVE-2026-15141MEDIUMReferer Validation Bypass in TL-WR820N Web Management InterfaceEPSS 0.1%CVE-2026-34126HIGHBluetooth Communication Uses Unencrypted Transmission During Initial Setup on TP-Link's Tapo L535E, P300 and D100CEPSS 0.1%CVE-2026-5040HIGHWeak Password Hashing Mechanism in TP-Link Deco M5EPSS 0.1%