Tcl develops a focused line of consumer and small-business networking devices, particularly mesh Wi-Fi systems and network switches, that sit in homes and branch offices where they handle both management traffic and sensitive local connectivity. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes across its product portfolio, reflecting the memory-safety and access-control demands of embedded network firmware. The exposure recurs through classic buffer-overflow conditions, out-of-bounds writes, stack-based overflows, improper access control, and information-disclosure weaknesses that are typical of embedded codebases with limited runtime protections. Defenders should prioritize inventory and patching of affected Tcl devices and restrict remote-management access; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tcl over time
Signals from CVEs in this vendor scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-21178CRITICAL An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead | Aug 5, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-24026CRITICAL A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overfl | Aug 5, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-26342CRITICAL A buffer overflow vulnerability exists in the confsrv ucloud_set_node_location functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead | Aug 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-24025CRITICAL A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overfl | Aug 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-24018CRITICAL A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overfl | Aug 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-24012CRITICAL A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overfl | Aug 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-24009CRITICAL A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overfl | Aug 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-22140CRITICAL An os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to | Aug 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-27178CRITICAL A denial of service vulnerability exists in the confctl_set_wan_cfg functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial | Aug 5, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-26346CRITICAL A denial of service vulnerability exists in the ucloud_del_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of s | Aug 5, 2022 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (50 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tcl.
Media articles that mention a CVE ID that affects a product developed by Tcl — matched by CVE ID, not by vendor name.