TP-Link Systems Inc.
First CVE: Apr 18, 2025Active for: 1 year
139
CVEs Published
More CVEs Published than 74% of tracked CNAs
69.5
Avg CVEs / Year
More Avg CVEs / Year than 87% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 60% of tracked CNAs
0.7%
In CISA KEV
Higher KEV Rate than 86% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by TP-Link Systems Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2025
15 months ago
Most Recent CVE
Jul 15, 2026
9 days ago
Top CVEs
All CVEs published by TP-Link Systems Inc. as a CNA, regardless of affected vendor or product.
139 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9377HIGH The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9.
This issue affects Archer | Aug 29, 2025 | 7.2 | 73 | YES | NO |
CVE-2026-0652HIGH On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attac | Feb 10, 2026 | 8.8 | 41 | NO | NO |
CVE-2026-9770HIGH Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem
that is shared across devices. An
attacker with access to the firmwa | Jul 15, 2026 | 8.6 | 40 | NO | NO |
CVE-2025-9961HIGH An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.
The exploit can only be conducted via a Man-In-The-Middle (MITM) | Sep 6, 2025 | 8.6 | 38 | NO | NO |
CVE-2026-11834HIGH A command
injection vulnerability has been identified in the DHCP option processing logic
in multiple TP-Link router models, due to insufficient validation of externally
supplied D | Jun 22, 2026 | 8.7 | 37 | NO | NO |
CVE-2025-6542CRITICAL An arbitrary OS command may be executed on the product by a remote unauthenticated attacker. | Oct 21, 2025 | 9.8 | 36 | NO | NO |
CVE-2026-8913HIGH A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management | Jun 8, 2026 | 8.5 | 34 | NO | NO |
CVE-2025-7851CRITICAL An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. | Oct 21, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-15428HIGH An OS
command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of
the domain name parameter. An adjacent attacker who can access the releva | Jul 14, 2026 | 8.5 | 33 | NO | NO |
CVE-2026-15427HIGH An OS command
injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of
parameters, all | Jul 14, 2026 | 8.6 | 33 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA139 CVEs
34%
62%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (2.2%)
Network58 (41.7%)
Unknown0 (0.0%)
Physical3 (2.2%)
Adjacent Network55 (39.6%)
Attack Complexity
Low131 (94.2%)
High8 (5.8%)
Unknown0 (0.0%)
User Interaction
None130 (93.5%)
Unknown0 (0.0%)
Required5 (3.6%)
Privileges Required
Low41 (29.5%)
High32 (23.0%)
None66 (47.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (139 CVEs).
CISA KEV
1 CVE
0.7% of CVEs· 86th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by TP-Link Systems Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by TP-Link Systems Inc. as a CNA — matched by CVE ID, not by organization name.