{"schema_version":1,"title":"TP-Link vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 99 vulnerabilities in TP-Link: 0 in the last 7 days and 48 in the last 90 days, 12 of them critical and 10 exploited in the wild. The most recent, CVE-2025-56565, was published on 16 September 2026. 22 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/tp-link","json_url":"https://junglewise.ai/threats/vendors/tp-link.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/tp-link","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":19,"all_time":99,"critical":12,"exploited":10,"last_7_days":0,"last_30_days":13,"last_90_days":48,"last_365_days":89},"latest":[{"cve":"CVE-2025-56565","cvss":7.6,"epss":0.0019,"slug":"cve-2025-56565-dd-wrt-firmware-cleartext-credential-storage-in-nvram","title":"DD-WRT firmware cleartext credential storage in NVRAM","severity":"high","exploited":false,"published_at":"2026-09-16T21:17:06.657+00:00","url":"https://junglewise.ai/threats/cve-2025-56565-dd-wrt-firmware-cleartext-credential-storage-in-nvram"},{"cve":"CVE-2026-84941","cvss":6.9,"epss":0.0047,"slug":"cve-2026-84941-tp-link-omada-controller-xxe-injection-in-saml-metadata-parsing","title":"TP-Link Omada Controller XXE injection in SAML metadata parsing","severity":"info","exploited":false,"published_at":"2026-09-11T00:19:57.633+00:00","url":"https://junglewise.ai/threats/cve-2026-84941-tp-link-omada-controller-xxe-injection-in-saml-metadata-parsing"},{"cve":"CVE-2026-17176","cvss":7.7,"epss":0.0368,"slug":"cve-2026-17176-tp-link-deco-be11000-os-command-injection-in-tddp-module","title":"TP-Link Deco BE11000 OS command injection in TDDP module","severity":"info","exploited":false,"published_at":"2026-09-11T00:17:26.707+00:00","url":"https://junglewise.ai/threats/cve-2026-17176-tp-link-deco-be11000-os-command-injection-in-tddp-module"},{"cve":"CVE-2026-76653","epss":0.0047,"slug":"cve-2026-76653-tp-link-archer-mr600-and-tl-mr6400-authentication-bypass-in-vpn","title":"TP-Link Archer MR600 and TL-MR6400 authentication bypass in VPN configuration","severity":"info","exploited":false,"published_at":"2026-09-10T21:17:45.433+00:00","url":"https://junglewise.ai/threats/cve-2026-76653-tp-link-archer-mr600-and-tl-mr6400-authentication-bypass-in-vpn"},{"cve":"CVE-2026-76652","cvss":0,"epss":0.0073,"slug":"cve-2026-76652-tp-link-archer-mr600-and-tl-mr6400-directory-traversal-in-file","title":"TP-Link Archer MR600 and TL-MR6400 directory traversal in file upload","severity":"info","exploited":false,"published_at":"2026-09-10T21:17:44.683+00:00","url":"https://junglewise.ai/threats/cve-2026-76652-tp-link-archer-mr600-and-tl-mr6400-directory-traversal-in-file"},{"cve":"CVE-2026-85384","cvss":8.1,"epss":0.0032,"slug":"cve-2026-85384-tp-link-re210-ac750-stack-buffer-overflow-in-httpd","title":"TP-Link RE210 AC750 stack buffer overflow in httpd","severity":"info","exploited":false,"published_at":"2026-09-08T19:20:07.763+00:00","url":"https://junglewise.ai/threats/cve-2026-85384-tp-link-re210-ac750-stack-buffer-overflow-in-httpd"},{"cve":"CVE-2026-81531","cvss":6.9,"epss":0.0067,"slug":"cve-2026-81531-tp-link-omada-controller-api-information-disclosure-in-controller","title":"TP-Link Omada Controller API information disclosure in controller initialization","severity":"info","exploited":false,"published_at":"2026-09-08T17:18:32.833+00:00","url":"https://junglewise.ai/threats/cve-2026-81531-tp-link-omada-controller-api-information-disclosure-in-controller"},{"cve":"CVE-2026-18330","cvss":6.1,"epss":0.0024,"slug":"cve-2026-18330-tp-link-archer-ax55-hard-coded-rsa-key-in-web-login","title":"TP-Link Archer AX55 hard-coded RSA key in web login","severity":"info","exploited":false,"published_at":"2026-09-03T23:17:19.4+00:00","url":"https://junglewise.ai/threats/cve-2026-18330-tp-link-archer-ax55-hard-coded-rsa-key-in-web-login"},{"cve":"CVE-2026-18167","cvss":7.7,"epss":0.0026,"slug":"cve-2026-18167-tp-link-archer-ax55-stack-based-buffer-overflow-in-easymesh","title":"TP-Link Archer AX55 stack-based buffer overflow in EasyMesh","severity":"info","exploited":false,"published_at":"2026-09-03T23:17:19.26+00:00","url":"https://junglewise.ai/threats/cve-2026-18167-tp-link-archer-ax55-stack-based-buffer-overflow-in-easymesh"},{"cve":"CVE-2026-76651","epss":0.0044,"slug":"cve-2026-76651-tp-link-tl-wr841n-buffer-overflow-in-http-service","title":"TP-Link TL-WR841N buffer overflow in HTTP service","severity":"info","exploited":false,"published_at":"2026-08-28T22:16:53.503+00:00","url":"https://junglewise.ai/threats/cve-2026-76651-tp-link-tl-wr841n-buffer-overflow-in-http-service"},{"cve":"CVE-2026-76650","epss":0.0027,"slug":"cve-2026-76650-tp-link-tl-wr841n-v14-null-pointer-dereference-in-upnp","title":"TP-Link TL-WR841N v14 NULL pointer dereference in UPnP","severity":"info","exploited":false,"published_at":"2026-08-28T22:16:53.38+00:00","url":"https://junglewise.ai/threats/cve-2026-76650-tp-link-tl-wr841n-v14-null-pointer-dereference-in-upnp"},{"cve":"CVE-2026-76649","epss":0.0027,"slug":"cve-2026-76649-tp-link-tl-wr841n-null-pointer-dereference-in-upnp-service","title":"TP-Link TL-WR841N NULL pointer dereference in UPnP service","severity":"info","exploited":false,"published_at":"2026-08-28T22:16:53.25+00:00","url":"https://junglewise.ai/threats/cve-2026-76649-tp-link-tl-wr841n-null-pointer-dereference-in-upnp-service"},{"cve":"CVE-2026-75118","cvss":8.7,"epss":0.0037,"slug":"cve-2026-75118-tp-link-tl-mr100-pre-authentication-stack-buffer-overflow-in-http","title":"TP-Link TL-MR100 pre-authentication stack buffer overflow in http_gdpr_decrypt","severity":"info","exploited":false,"published_at":"2026-08-28T22:16:52.88+00:00","url":"https://junglewise.ai/threats/cve-2026-75118-tp-link-tl-mr100-pre-authentication-stack-buffer-overflow-in-http"},{"cve":"CVE-2026-76784","cvss":0,"epss":0.002,"slug":"cve-2026-76784-tp-link-kasa-insufficient-cryptographic-protection-in-device","title":"TP-Link Kasa insufficient cryptographic protection in device communication","severity":"info","exploited":false,"published_at":"2026-08-26T18:17:01.903+00:00","url":"https://junglewise.ai/threats/cve-2026-76784-tp-link-kasa-insufficient-cryptographic-protection-in-device"},{"cve":"CVE-2026-78541","cvss":8.8,"epss":0.0228,"slug":"cve-2026-78541-tp-link-archer-be3600-stored-os-command-injection-in-parental","title":"TP-Link Archer BE3600 stored OS command injection in parental control","severity":"info","exploited":false,"published_at":"2026-08-24T19:17:04.553+00:00","url":"https://junglewise.ai/threats/cve-2026-78541-tp-link-archer-be3600-stored-os-command-injection-in-parental"},{"cve":"CVE-2026-9254","epss":0.0306,"slug":"cve-2026-9254-tp-link-archer-os-command-injection-in-parental-control","title":"TP-Link Archer OS command injection in parental control","severity":"info","exploited":false,"published_at":"2026-08-24T18:17:34.973+00:00","url":"https://junglewise.ai/threats/cve-2026-9254-tp-link-archer-os-command-injection-in-parental-control"},{"cve":"CVE-2026-16348","epss":0.0196,"slug":"cve-2026-16348-tp-link-archer-be800-command-injection-in-vpn","title":"TP-Link Archer BE800 command injection in VPN","severity":"info","exploited":false,"published_at":"2026-08-24T18:16:59.71+00:00","url":"https://junglewise.ai/threats/cve-2026-16348-tp-link-archer-be800-command-injection-in-vpn"},{"cve":"CVE-2026-15469","cvss":0,"epss":0.0038,"slug":"cve-2026-15469-tp-link-deco-hardcoded-cryptographic-key-in-mesh-authentication","title":"TP-Link Deco hardcoded cryptographic key in mesh authentication","severity":"info","exploited":false,"published_at":"2026-08-24T17:17:21.587+00:00","url":"https://junglewise.ai/threats/cve-2026-15469-tp-link-deco-hardcoded-cryptographic-key-in-mesh-authentication"},{"cve":"CVE-2026-17252","cvss":6.5,"epss":0.0027,"slug":"cve-2026-17252-tp-link-tl-mr6400-v7-stack-based-buffer-overflow-in-login-handler","title":"TP-Link TL-MR6400 v7 stack-based buffer overflow in login handler","severity":"info","exploited":false,"published_at":"2026-08-21T18:16:47.803+00:00","url":"https://junglewise.ai/threats/cve-2026-17252-tp-link-tl-mr6400-v7-stack-based-buffer-overflow-in-login-handler"},{"cve":"CVE-2026-17251","cvss":5.3,"epss":0.0047,"slug":"cve-2026-17251-tp-link-tl-mr6400-null-pointer-dereference-in-http-parsing","title":"TP-Link TL-MR6400 NULL pointer dereference in HTTP parsing","severity":"info","exploited":false,"published_at":"2026-08-21T18:16:47.66+00:00","url":"https://junglewise.ai/threats/cve-2026-17251-tp-link-tl-mr6400-null-pointer-dereference-in-http-parsing"},{"cve":"CVE-2026-17250","epss":0.003,"slug":"cve-2026-17250-tp-link-tl-mr6400-stack-buffer-overflow-in-firmware-update","title":"TP-Link TL-MR6400 stack buffer overflow in firmware update","severity":"info","exploited":false,"published_at":"2026-08-21T18:16:47.45+00:00","url":"https://junglewise.ai/threats/cve-2026-17250-tp-link-tl-mr6400-stack-buffer-overflow-in-firmware-update"},{"cve":"CVE-2026-9033","cvss":4.3,"epss":0.0028,"slug":"cve-2026-9033-tp-link-deco-captive-portal-session-termination-denial-of-service","title":"TP-Link Deco captive portal session termination denial of service","severity":"medium","exploited":false,"published_at":"2026-08-20T19:17:04.95+00:00","url":"https://junglewise.ai/threats/cve-2026-9033-tp-link-deco-captive-portal-session-termination-denial-of-service"},{"cve":"CVE-2026-19683","cvss":7.4,"epss":0.0025,"slug":"cve-2026-19683-tp-link-omada-gateways-unencrypted-ddns-credential-transmission","title":"TP-Link Omada Gateways unencrypted DDNS credential transmission","severity":"high","exploited":false,"published_at":"2026-08-20T19:16:51.303+00:00","url":"https://junglewise.ai/threats/cve-2026-19683-tp-link-omada-gateways-unencrypted-ddns-credential-transmission"},{"cve":"CVE-2026-19586","cvss":9.8,"epss":0.057,"slug":"cve-2026-19586-tp-link-omada-gateways-os-command-injection-in-openvpn","title":"TP-Link Omada gateways OS command injection in OpenVPN authentication","severity":"critical","exploited":false,"published_at":"2026-08-20T19:16:51.103+00:00","url":"https://junglewise.ai/threats/cve-2026-19586-tp-link-omada-gateways-os-command-injection-in-openvpn"},{"cve":"CVE-2026-8619","cvss":7.5,"epss":0.0087,"slug":"cve-2026-8619-tp-link-4g-lte-router-denial-of-service-via-malformed-http-request","title":"TP-Link 4G/LTE router denial of service via malformed HTTP request","severity":"high","exploited":false,"published_at":"2026-08-20T00:16:53.157+00:00","url":"https://junglewise.ai/threats/cve-2026-8619-tp-link-4g-lte-router-denial-of-service-via-malformed-http-request"}],"vendor":{"hub":true,"name":"TP-Link","slug":"tp-link","homepage":"https://www.tp-link.com/","description":"A global provider of consumer and business networking products, including routers, switches, and wireless equipment.","url":"https://junglewise.ai/threats/vendors/tp-link"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-17","critical":1,"exploited":0,"vulnerabilities":7},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2018-6530","cvss":9.8,"slug":"cve-2018-6530-d-link-multiple-routers-os-command-injection-vulnerability","title":"D-Link Multiple Routers OS Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2022-09-08T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2018-6530-d-link-multiple-routers-os-command-injection-vulnerability"},{"cve":"CVE-2021-45382","cvss":9.8,"slug":"cve-2021-45382-d-link-multiple-routers-remote-code-execution-vulnerability","title":"D-Link Multiple Routers Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-04-04T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-45382-d-link-multiple-routers-remote-code-execution-vulnerability"},{"cve":"CVE-2019-16920","cvss":9.8,"slug":"cve-2019-16920-d-link-multiple-routers-command-injection-vulnerability","title":"D-Link Multiple Routers Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2019-16920-d-link-multiple-routers-command-injection-vulnerability"},{"cve":"CVE-2023-33538","cvss":8.8,"epss":0.9057,"slug":"cve-2023-33538-tp-link-multiple-routers-command-injection-in-wlannetworkrpm","title":"TP-Link Multiple Routers command injection in WlanNetworkRpm","severity":"critical","exploited":true,"published_at":"2025-06-16T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-33538-tp-link-multiple-routers-command-injection-in-wlannetworkrpm"},{"cve":"CVE-2020-24363","cvss":8.8,"epss":0.1261,"slug":"cve-2020-24363-tp-link-tl-wa855re-missing-authentication-for-factory-reset","title":"TP-Link TL-WA855RE missing authentication for factory reset","severity":"critical","exploited":true,"published_at":"2025-09-02T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2020-24363-tp-link-tl-wa855re-missing-authentication-for-factory-reset"},{"cve":"CVE-2023-1389","cvss":8.8,"slug":"cve-2023-1389-tp-link-archer-ax-21-command-injection-vulnerability","title":"TP-Link Archer AX-21 Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2023-05-01T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-1389-tp-link-archer-ax-21-command-injection-vulnerability"},{"cve":"CVE-2016-6277","cvss":8.8,"slug":"cve-2016-6277-netgear-multiple-routers-remote-code-execution-vulnerability","title":"NETGEAR Multiple Routers Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-07T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2016-6277-netgear-multiple-routers-remote-code-execution-vulnerability"},{"cve":"CVE-2015-3035","cvss":7.5,"slug":"cve-2015-3035-tp-link-multiple-archer-devices-directory-traversal-vulnerability","title":"TP-Link Multiple Archer Devices Directory Traversal Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2015-3035-tp-link-multiple-archer-devices-directory-traversal-vulnerability"},{"cve":"CVE-2025-9377","cvss":7.2,"epss":0.3086,"slug":"cve-2025-9377-tp-link-archer-c7-and-tl-wr841n-os-command-injection-in-parental","title":"TP-Link Archer C7 and TL-WR841N OS command injection in Parental Control","severity":"critical","exploited":true,"published_at":"2025-09-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-9377-tp-link-archer-c7-and-tl-wr841n-os-command-injection-in-parental"},{"cve":"CVE-2023-50224","cvss":6.5,"epss":0.0146,"slug":"cve-2023-50224-tp-link-tl-wr841n-authentication-bypass-in-httpd-service","title":"TP-Link TL-WR841N authentication bypass in httpd service","severity":"critical","exploited":true,"published_at":"2025-09-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-50224-tp-link-tl-wr841n-authentication-bypass-in-httpd-service"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"TP-Link Tapo C520WS","slug":"tapo-c520ws","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/tapo-c520ws"},{"name":"TP-Link TL-WR841N","slug":"tl-wr841n","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/tl-wr841n"},{"name":"TP-Link Archer AX53","slug":"archer-ax53","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/archer-ax53"},{"name":"TP-Link Archer Ax53 Firmware","slug":"archer-ax53-firmware","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/archer-ax53-firmware"},{"name":"TP-Link Multiple Routers","slug":"multiple-routers","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/multiple-routers"},{"name":"TP-Link Tapo C520WS firmware","slug":"tapo-c520ws-firmware","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/tapo-c520ws-firmware"},{"name":"TP-Link TL-MR6400","slug":"tl-mr6400","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/tl-mr6400"},{"name":"TP-Link Archer MR600","slug":"archer-mr600","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/archer-mr600"},{"name":"TP-Link Archer BE230","slug":"archer-be230","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/archer-be230"},{"name":"TP-Link Archer Be230 Firmware","slug":"archer-be230-firmware","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/archer-be230-firmware"},{"name":"TP-Link Archer BE3600","slug":"archer-be3600","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/archer-be3600"},{"name":"TP-Link Deco BE23","slug":"deco-be23","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/deco-be23"},{"name":"TP-Link Deco BE25","slug":"deco-be25","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/deco-be25"},{"name":"TP-Link Deco BE65","slug":"deco-be65","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/deco-be65"},{"name":"TP-Link Deco BE65 Pro","slug":"deco-be65-pro","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/deco-be65-pro"},{"name":"TP-Link Deco BE85","slug":"deco-be85","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/deco-be85"},{"name":"TP-Link Archer AX55","slug":"archer-ax55","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/archer-ax55"},{"name":"TP-Link Archer VX1800v","slug":"archer-vx1800v","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/archer-vx1800v"},{"name":"TP-Link Deco BE65-PoE","slug":"deco-be65-poe","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/deco-be65-poe"},{"name":"TP-Link Omada","slug":"omada","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/omada"},{"name":"TP-Link Tapo C200","slug":"tapo-c200","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/tapo-c200"},{"name":"TP-Link TL-WR940N","slug":"tl-wr940n","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/tl-wr940n"}]}