Vulnerabilities (CVE)

Filtered by vendor Tp-link Subscribe
Total 381 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-46683 1 Tp-link 2 Er7206, Er7206 Firmware 2024-11-21 N/A 7.2 HIGH
A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection . An attacker can make an authenticated HTTP request to trigger this vulnerability.
CVE-2023-46539 1 Tp-link 2 Tl-wr886n, Tl-wr886n Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function registerRequestHandle.
CVE-2023-46538 1 Tp-link 2 Tl-wr886n, Tl-wr886n Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkResetVeriRegister.
CVE-2023-46537 1 Tp-link 2 Tl-wr886n, Tl-wr886n Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getRegVeriRegister.
CVE-2023-46536 1 Tp-link 2 Tl-wr886n, Tl-wr886n Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkRegVeriRegister.
CVE-2023-46535 1 Tp-link 2 Tl-wr886n, Tl-wr886n Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getResetVeriRegister.
CVE-2023-46534 1 Tp-link 2 Tl-wr886n, Tl-wr886n Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function modifyAccPwdRegister.
CVE-2023-46527 1 Tp-link 2 Tl-wr886n, Tl-wr886n Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 was discovered to contain a stack overflow via the function bindRequestHandle.
CVE-2023-46526 1 Tp-link 2 Tl-wr886n, Tl-wr886n Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function resetCloudPwdRegister.
CVE-2023-46525 1 Tp-link 2 Tl-wr886n, Tl-wr886n Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function loginRegister.
CVE-2023-46523 1 Tp-link 2 Tl-wr886n, Tl-wr886n Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function upgradeInfoRegister.
CVE-2023-46522 1 Tp-link 2 Tl-wr886n, Tl-wr886n Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-LINK device TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 were discovered to contain a stack overflow via the function deviceInfoRegister.
CVE-2023-46521 1 Tp-link 2 Tl-wr886n, Tl-wr886n Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function RegisterRegister.
CVE-2023-46520 1 Tp-link 2 Tl-wr886n, Tl-wr886n Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function uninstallPluginReqHandle.
CVE-2023-46373 1 Tp-link 2 Tl-wdr7660, Tl-wdr7660 Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-Link TL-WDR7660 2.0.30 has a stack overflow vulnerability via the function deviceInfoJsonToBincauses.
CVE-2023-46371 1 Tp-link 2 Tl-wdr7660, Tl-wdr7660 Firmware 2024-11-21 N/A 9.8 CRITICAL
TP-Link device TL-WDR7660 2.0.30 and TL-WR886N 2.0.12 has a stack overflow vulnerability via the function upgradeInfoJsonToBin.
CVE-2023-43482 1 Tp-link 2 Er7206, Er7206 Firmware 2024-11-21 N/A 7.2 HIGH
A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
CVE-2023-43318 1 Tp-link 2 Tl-sg2210p, Tl-sg2210p Firmware 2024-11-21 N/A 8.8 HIGH
TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.
CVE-2023-43138 1 Tp-link 2 Tl-er5120g, Tl-er5120g Firmware 2024-11-21 N/A 8.8 HIGH
TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT rules after authentication, and the rule name has an injection point.
CVE-2023-43137 1 Tp-link 2 Tl-er5120g, Tl-er5120g Firmware 2024-11-21 N/A 8.8 HIGH
TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rules after authentication, and the rule name parameter has injection points.