Vendor
TP-Link vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 99 vulnerabilities in TP-Link: 0 in the last 7 days and 48 in the last 90 days, 12 of them critical and 10 exploited in the wild. The most recent, CVE-2025-56565, was published on 16 September 2026. It has 22 technologies with a page of its own.
- Last 7 days
- 0
- Last 90 days
- 48
- Critical, all time
- 12
- Exploited in the wild
- 10
About TP-Link
A global provider of consumer and business networking products, including routers, switches, and wireless equipment.
TP-Link technologies
- TP-Link Tapo C520WS13
- TP-Link TL-WR841N8
- TP-Link Archer AX537
- TP-Link Archer Ax53 Firmware7
- TP-Link Multiple Routers6
- TP-Link Tapo C520WS firmware6
- TP-Link TL-MR64006
- TP-Link Archer MR6005
- TP-Link Archer BE2304
- TP-Link Archer Be230 Firmware4
- TP-Link Archer BE36004
- TP-Link Deco BE234
- TP-Link Deco BE254
- TP-Link Deco BE654
- TP-Link Deco BE65 Pro4
- TP-Link Deco BE854
- TP-Link Archer AX553
- TP-Link Archer VX1800v3
- TP-Link Deco BE65-PoE3
- TP-Link Omada3
- TP-Link Tapo C2003
- TP-Link TL-WR940N3
Latest TP-Link vulnerabilities
- CVE-2025-56565: DD-WRT firmware cleartext credential storage in NVRAMhighCVSS 7.6EPSS 0.2%
- CVE-2026-84941: TP-Link Omada Controller XXE injection in SAML metadata parsinginfoCVSS 6.9EPSS 0.5%
- CVE-2026-17176: TP-Link Deco BE11000 OS command injection in TDDP moduleinfoCVSS 7.7EPSS 3.7%
- CVE-2026-76653: TP-Link Archer MR600 and TL-MR6400 authentication bypass in VPN configurationinfoEPSS 0.5%
- CVE-2026-76652: TP-Link Archer MR600 and TL-MR6400 directory traversal in file uploadinfoCVSS 0EPSS 0.7%
- CVE-2026-85384: TP-Link RE210 AC750 stack buffer overflow in httpdinfoCVSS 8.1EPSS 0.3%
- CVE-2026-81531: TP-Link Omada Controller API information disclosure in controller initializationinfoCVSS 6.9EPSS 0.7%
- CVE-2026-18330: TP-Link Archer AX55 hard-coded RSA key in web logininfoCVSS 6.1EPSS 0.2%
- CVE-2026-18167: TP-Link Archer AX55 stack-based buffer overflow in EasyMeshinfoCVSS 7.7EPSS 0.3%
- CVE-2026-76651: TP-Link TL-WR841N buffer overflow in HTTP serviceinfoEPSS 0.4%
- CVE-2026-76650: TP-Link TL-WR841N v14 NULL pointer dereference in UPnPinfoEPSS 0.3%
- CVE-2026-76649: TP-Link TL-WR841N NULL pointer dereference in UPnP serviceinfoEPSS 0.3%
- CVE-2026-75118: TP-Link TL-MR100 pre-authentication stack buffer overflow in http_gdpr_decryptinfoCVSS 8.7EPSS 0.4%
- CVE-2026-76784: TP-Link Kasa insufficient cryptographic protection in device communicationinfoCVSS 0EPSS 0.2%
- CVE-2026-78541: TP-Link Archer BE3600 stored OS command injection in parental controlinfoCVSS 8.8EPSS 2.3%
- CVE-2026-9254: TP-Link Archer OS command injection in parental controlinfoEPSS 3.1%
- CVE-2026-16348: TP-Link Archer BE800 command injection in VPNinfoEPSS 2.0%
- CVE-2026-15469: TP-Link Deco hardcoded cryptographic key in mesh authenticationinfoCVSS 0EPSS 0.4%
- CVE-2026-17252: TP-Link TL-MR6400 v7 stack-based buffer overflow in login handlerinfoCVSS 6.5EPSS 0.3%
- CVE-2026-17251: TP-Link TL-MR6400 NULL pointer dereference in HTTP parsinginfoCVSS 5.3EPSS 0.5%
- CVE-2026-17250: TP-Link TL-MR6400 stack buffer overflow in firmware updateinfoEPSS 0.3%
- CVE-2026-9033: TP-Link Deco captive portal session termination denial of servicemediumCVSS 4.3EPSS 0.3%
- CVE-2026-19683: TP-Link Omada Gateways unencrypted DDNS credential transmissionhighCVSS 7.4EPSS 0.3%
- CVE-2026-19586: TP-Link Omada gateways OS command injection in OpenVPN authenticationcriticalCVSS 9.8EPSS 5.7%
- CVE-2026-8619: TP-Link 4G/LTE router denial of service via malformed HTTP requesthighCVSS 7.5EPSS 0.9%
Most severe TP-Link vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2018-6530: D-Link Multiple Routers OS Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2021-45382: D-Link Multiple Routers Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2019-16920: D-Link Multiple Routers Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-33538: TP-Link Multiple Routers command injection in WlanNetworkRpmcriticalexploited in the wildCVSS 8.8EPSS 90.6%
- CVE-2020-24363: TP-Link TL-WA855RE missing authentication for factory resetcriticalexploited in the wildCVSS 8.8EPSS 12.6%
- CVE-2023-1389: TP-Link Archer AX-21 Command Injection Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2016-6277: NETGEAR Multiple Routers Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2015-3035: TP-Link Multiple Archer Devices Directory Traversal Vulnerabilitycriticalexploited in the wildCVSS 7.5
- CVE-2025-9377: TP-Link Archer C7 and TL-WR841N OS command injection in Parental Controlcriticalexploited in the wildCVSS 7.2EPSS 30.9%
- CVE-2023-50224: TP-Link TL-WR841N authentication bypass in httpd servicecriticalexploited in the wildCVSS 6.5EPSS 1.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 3 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 6 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 3 | 0 | |
| 3 Aug 2026 | 7 | 0 | |
| 10 Aug 2026 | 4 | 0 | |
| 17 Aug 2026 | 7 | 1 | |
| 24 Aug 2026 | 9 | 0 | |
| 31 Aug 2026 | 2 | 0 | |
| 7 Sep 2026 | 6 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/tp-link.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "TP-Link vulnerabilities", https://junglewise.ai/threats/vendors/tp-link, 26 September 2026.