TP-Link's vulnerability footprint spans a very broad portfolio of consumer and small-business networking devices including routers and wireless access points, many of which achieve significant global deployment and often remain in service beyond their support lifecycle. The recurring exposure centers on models such as the TL-WR841N and TL-WR886N router lines and their associated firmware, establishing a durable pattern across the vendor's wireless and wired networking product families. While the vendor's disclosures are substantial in volume and prevalence within the networking-device landscape, weakness-class clustering has not emerged as a defining pattern, and the exposure does not skew toward either critical severity or elevated exploitation tendency. Defenders should inventory affected TP-Link devices across networks, prioritize internet-exposed instances for isolation or firmware updates, and recognize that many devices may lack timely patches due to vendor support constraints. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tp Link over time
Signals from CVEs in this vendor scope (523 CVEs).
523 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1389HIGH TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoin | Mar 15, 2023 | 8.8 | 98 | YES | YES |
CVE-2015-3035HIGH Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 | Apr 22, 2015 | 7.5 | 96 | YES | YES |
CVE-2023-33538HIGH TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm . | Jun 7, 2023 | 8.8 | 86 | YES | NO |
CVE-2020-24363HIGH TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The atta | Aug 31, 2020 | 8.8 | 84 | YES | YES |
CVE-2021-41653CRITICAL The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address | Nov 13, 2021 | 9.8 | 83 | NO | YES |
CVE-2013-2578HIGH cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attacker | Oct 11, 2013 | 10.0 | 81 | NO | YES |
CVE-2022-25061CRITICAL TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute. | Feb 25, 2022 | 9.8 | 80 | NO | YES |
CVE-2020-28347CRITICAL tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this issue exists because of an inc | Nov 8, 2020 | 9.8 | 80 | NO | YES |
CVE-2012-5687HIGH Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attacke | Nov 1, 2012 | 7.8 | 78 | NO | YES |
CVE-2021-4045CRITICAL TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. | Mar 10, 2022 | 9.8 | 77 | NO | YES |
Signals from CVEs in this vendor scope (523 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tp Link.
Media articles that mention a CVE ID that affects a product developed by Tp Link — matched by CVE ID, not by vendor name.