Search
Find a vulnerability
Search criteria
195 vulnerabilities
CVE-2026-102370 (GCVE-0-2026-102370)
Vulnerability from cvelistv5 – Published: 2026-10-01 20:47 – Updated: 2026-10-01 21:01
VLAI
EPSS
VEX
Title
Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71
Summary
Kasa EC70 v4
and EC71 v4 do not logically disable the production debug interface at the
firmware or chip level and do not lock the bootloader. Although the debug traces are physically
severed during manufacturing, an attacker with physical access can restore the
connection, interrupt the boot process, and manipulate boot parameters to enter
a non-standard initialization path that exposes an unauthenticated root shell
during startup.
Successful exploitation may allow an
attacker with physical access to obtain root-level command access during device
startup, resulting in loss of confidentiality, integrity, and availability for
the affected device. Exploitation requires device disassembly, restoration of
the severed debug connection, and manipulation of the boot process.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 21:01 UTC
CWE
- CWE-1191 - On-Chip debug and test interface with improper access control
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/ec71/… | patch |
| https://www.tp-link.com/us/support/download/ec70/… | patch |
| https://www.tp-link.com/us/support/faq/5324/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Kasa EC70 V4 |
Affected:
0 , < 2.4.3 Build 20260902 rel.4511
(custom)
|
|
| TP-Link Systems Inc. | Kasa EC71 V4 |
Affected:
0 , < 2.4.3 Build 20260902 rel.4511
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102370",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T21:01:19.841347Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T21:01:44.613Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Kasa EC70 V4",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.4.3 Build 20260902 rel.4511",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Kasa EC71 V4",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.4.3 Build 20260902 rel.4511",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Christopher Childress"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eKasa EC70 v4\nand EC71 v4 do not logically disable the production debug interface at the\nfirmware or chip level and do not lock the bootloader.\u0026nbsp; Although the debug traces are physically\nsevered during manufacturing, an attacker with physical access can restore the\nconnection, interrupt the boot process, and manipulate boot parameters to enter\na non-standard initialization path that exposes an unauthenticated root shell\nduring startup.\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful exploitation may allow an\nattacker with physical access to obtain root-level command access during device\nstartup, resulting in loss of confidentiality, integrity, and availability for\nthe affected device. Exploitation requires device disassembly, restoration of\nthe severed debug connection, and manipulation of the boot process.\u003cb\u003e \u003c/b\u003e\u003c/p\u003e"
}
],
"value": "Kasa EC70 v4\nand EC71 v4 do not logically disable the production debug interface at the\nfirmware or chip level and do not lock the bootloader.\u00a0 Although the debug traces are physically\nsevered during manufacturing, an attacker with physical access can restore the\nconnection, interrupt the boot process, and manipulate boot parameters to enter\na non-standard initialization path that exposes an unauthenticated root shell\nduring startup.\n\n\n\n\n\n\n\n\n\nSuccessful exploitation may allow an\nattacker with physical access to obtain root-level command access during device\nstartup, resulting in loss of confidentiality, integrity, and availability for\nthe affected device. Exploitation requires device disassembly, restoration of\nthe severed debug connection, and manipulation of the boot process."
}
],
"impacts": [
{
"capecId": "CAPEC-116",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-116 Excavation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "PHYSICAL",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1191",
"description": "CWE-1191 On-Chip debug and test interface with improper access control",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T20:47:30.211Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/ec71/v4/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5324/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-102370",
"datePublished": "2026-10-01T20:47:30.211Z",
"dateReserved": "2026-09-28T23:32:02.361Z",
"dateUpdated": "2026-10-01T21:01:44.613Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84682 (GCVE-0-2026-84682)
Vulnerability from cvelistv5 – Published: 2026-10-01 18:48 – Updated: 2026-10-02 03:55
VLAI
EPSS
VEX
Title
TDDPv2 setProductVer Command Injection in Archer AX90
Summary
A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot.
Successful exploitation may result in complete device compromise through arbitrary command execution with root privileges.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 00:00 UTC
CWE
- CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/arche… | patch |
| https://www.tp-link.com/en/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5323/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Archer AX90 v1 |
Affected:
0 , < 1.1.4 Build 20260927
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-84682",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T03:55:36.196Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"tddp"
],
"product": "Archer AX90 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.4 Build 20260927",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Can Oztas"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003eA command injection vulnerability exists in the TDDPv2 service (\u003ccode\u003e/usr/bin/tddp\u003c/code\u003e) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the \u003ccode\u003esetProductVer\u003c/code\u003e command handler to execute arbitrary operating system commands as root during device boot.\u0026nbsp;\u003c/div\u003e\u003cdiv\u003eSuccessful exploitation may result in complete device compromise through arbitrary command execution with root privileges.\u003c/div\u003e"
}
],
"value": "A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot.\u00a0\n\nSuccessful exploitation may result in complete device compromise through arbitrary command execution with root privileges."
}
],
"impacts": [
{
"capecId": "CAPEC-88",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-88 OS Command Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:48:42.953Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/archer-ax90/v1/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-ax90/v1/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5323/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "TDDPv2 setProductVer Command Injection in Archer AX90",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-84682",
"datePublished": "2026-10-01T18:48:42.953Z",
"dateReserved": "2026-09-01T22:24:51.457Z",
"dateUpdated": "2026-10-02T03:55:36.196Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-8618 (GCVE-0-2026-8618)
Vulnerability from cvelistv5 – Published: 2026-10-01 18:16 – Updated: 2026-10-01 18:36
VLAI
EPSS
VEX
Title
Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x91 on Deco M9 Plus
Summary
A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:35 UTC
CWE
- CWE-121 - Stack-based buffer overflow
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/deco-… | patch |
| https://www.tp-link.com/us/support/download/deco-… | patch |
| https://www.tp-link.com/us/support/faq/5322/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Deco M9 Plus V2 |
Affected:
0 , < 1.9.2 Build 20260818
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-8618",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:35:59.010450Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:36:18.919Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"tddp"
],
"product": "Deco M9 Plus V2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.9.2 Build 20260818",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Isa Roovers"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003eA stack-based buffer overflow vulnerability exists in the TDDPv2 service (\u003ccode\u003e/usr/bin/tddp\u003c/code\u003e) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype \u003ccode\u003e0x91\u003c/code\u003e handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets.\u003c/div\u003e"
}
],
"value": "A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets."
}
],
"impacts": [
{
"capecId": "CAPEC-123",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-123 Buffer Manipulation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "CWE-121 Stack-based buffer overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:16:32.107Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/deco-m9-plus/v2/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/deco-m9-plus/v2/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5322/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x91 on Deco M9 Plus",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-8618",
"datePublished": "2026-10-01T18:16:32.107Z",
"dateReserved": "2026-05-14T18:04:17.050Z",
"dateUpdated": "2026-10-01T18:36:18.919Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102369 (GCVE-0-2026-102369)
Vulnerability from cvelistv5 – Published: 2026-10-01 17:42 – Updated: 2026-10-01 18:08
VLAI
EPSS
VEX
Title
Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 & C200
Summary
Tapo C120 v1 and C200 V5
do not adequately protect login challenge data or sanitize
attacker-controlled input processed by the MacTool handler. An unauthenticated
attacker on the same local network can replay login challenge data to obtain an
administrative session, enable a privileged service that becomes accessible
after a reboot, and submit crafted input to execute arbitrary commands within
the device management process.
Successful
exploitation may allow arbitrary command execution on the camera and compromise
the confidentiality, integrity, and availability of the affected device.
Exploitation requires access from the same local network, replay of the login
challenge data, activation of the privileged service, and a device reboot.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:07 UTC
CWE
- CWE-287 - Improper Authentication
Assigner
References
5 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C200 v5 |
Affected:
0 , < V5_1.4.6 Build 260709 Rel.27675n
(custom)
|
|
| TP-Link Systems Inc. | Tapo C120 v1 |
Affected:
0 , < V1_1.9.4 Build 260813 Rel.79754n
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102369",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:07:54.890490Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:08:05.015Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Tapo C200 v5",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Tapo C120 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eTapo C120 v1 and C200 V5\ndo not adequately protect login challenge data or sanitize\nattacker-controlled input processed by the MacTool handler. An unauthenticated\nattacker on the same local network can replay login challenge data to obtain an\nadministrative session, enable a privileged service that becomes accessible\nafter a reboot, and submit crafted input to execute arbitrary commands within\nthe device management process.\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful\nexploitation may allow arbitrary command execution on the camera and compromise\nthe confidentiality, integrity, and availability of the affected device.\nExploitation requires access from the same local network, replay of the login\nchallenge data, activation of the privileged service, and a device reboot.\u003c/p\u003e"
}
],
"value": "Tapo C120 v1 and C200 V5\ndo not adequately protect login challenge data or sanitize\nattacker-controlled input processed by the MacTool handler. An unauthenticated\nattacker on the same local network can replay login challenge data to obtain an\nadministrative session, enable a privileged service that becomes accessible\nafter a reboot, and submit crafted input to execute arbitrary commands within\nthe device management process.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow arbitrary command execution on the camera and compromise\nthe confidentiality, integrity, and availability of the affected device.\nExploitation requires access from the same local network, replay of the login\nchallenge data, activation of the privileged service, and a device reboot."
}
],
"impacts": [
{
"capecId": "CAPEC-21",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-21 Exploitation of Trusted Identifiers"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:42:25.482Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5321/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 \u0026 C200",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-102369",
"datePublished": "2026-10-01T17:42:25.482Z",
"dateReserved": "2026-09-28T23:02:41.717Z",
"dateUpdated": "2026-10-01T18:08:05.015Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-78578 (GCVE-0-2026-78578)
Vulnerability from cvelistv5 – Published: 2026-10-01 17:42 – Updated: 2026-10-01 18:08
VLAI
EPSS
VEX
Title
Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Service Vulnerability in TP-Link Tapo C120 & C200
Summary
Tapo C120 v1 and C200 v5
do not enforce authentication for do method HTTPS onboarding connect actions
after initial setup. An unauthenticated adjacent
attacker can submit unauthorized wireless configuration parameters, causing the
camera to attempt connection to a different network.
Successful
exploitation disconnects the camera from its intended wireless network, making
it unreachable on its management address, resulting in a denial-of-service
condition.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:08 UTC
CWE
- CWE-306 - Missing authentication for critical function
Assigner
References
5 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C200 v5 |
Affected:
0 , < V5_1.4.6 Build 260709 Rel.27675n
(custom)
|
|
| TP-Link Systems Inc. | Tapo C120 v1 |
Affected:
0 , < V1_1.9.4 Build 260813 Rel.79754n
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-78578",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:08:21.543786Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:08:30.649Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Tapo C200 v5",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Tapo C120 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eTapo C120 v1 and C200 v5\ndo not enforce authentication for do method HTTPS onboarding connect actions\nafter initial setup.\u0026nbsp; An unauthenticated adjacent\nattacker can submit unauthorized wireless configuration parameters, causing the\ncamera to attempt connection to a different network.\u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation disconnects the camera from its intended wireless network, making\nit unreachable on its management address, resulting in a denial-of-service\ncondition.\u003c/p\u003e"
}
],
"value": "Tapo C120 v1 and C200 v5\ndo not enforce authentication for do method HTTPS onboarding connect actions\nafter initial setup.\u00a0 An unauthenticated adjacent\nattacker can submit unauthorized wireless configuration parameters, causing the\ncamera to attempt connection to a different network.\n\n\n\n\n\nSuccessful\nexploitation disconnects the camera from its intended wireless network, making\nit unreachable on its management address, resulting in a denial-of-service\ncondition."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "CWE-306 Missing authentication for critical function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:42:05.535Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5321/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated do Method Onboarding Connect Allows Wi\u2011Fi Reconfiguration Denial of Service Vulnerability in TP-Link Tapo C120 \u0026 C200",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-78578",
"datePublished": "2026-10-01T17:42:05.535Z",
"dateReserved": "2026-08-24T20:46:19.845Z",
"dateUpdated": "2026-10-01T18:08:30.649Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-78577 (GCVE-0-2026-78577)
Vulnerability from cvelistv5 – Published: 2026-10-01 17:41 – Updated: 2026-10-01 18:08
VLAI
EPSS
VEX
Title
Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200
Summary
Tapo C120 v1 and C200 V5
contain a vulnerability in the HTTPS onboarding scan function due to missing authentication.
After initial setup, an unauthenticated attacker on the same local network can
invoke the scan action and retrieve nearby wireless access-point metadata,
including SSIDs, BSSIDs, authentication and encryption modes, and
signal-strength information.
Successful
exploitation may disclose information about the wireless environment
surrounding the camera, allowing an attacker to learn elements of the local
wireless topology.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:08 UTC
CWE
- CWE-306 - Missing authentication for critical function
Assigner
References
5 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C200 v5 |
Affected:
0 , < V5_1.4.6 Build 260709 Rel.27675n
(custom)
|
|
| TP-Link Systems Inc. | Tapo C120 v1 |
Affected:
0 , < V1_1.9.4 Build 260813 Rel.79754n
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-78577",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:08:50.711151Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:08:59.956Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Tapo C200 v5",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Tapo C120 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eTapo C120 v1 and C200 V5\ncontain a vulnerability in the HTTPS onboarding scan function due to missing authentication.\nAfter initial setup, an unauthenticated attacker on the same local network can\ninvoke the scan action and retrieve nearby wireless access-point metadata,\nincluding SSIDs, BSSIDs, authentication and encryption modes, and\nsignal-strength information.\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful\nexploitation may disclose information about the wireless environment\nsurrounding the camera, allowing an attacker to learn elements of the local\nwireless topology.\u0026nbsp;\u003cb\u003e\u003c/b\u003e\u003c/p\u003e"
}
],
"value": "Tapo C120 v1 and C200 V5\ncontain a vulnerability in the HTTPS onboarding scan function due to missing authentication.\nAfter initial setup, an unauthenticated attacker on the same local network can\ninvoke the scan action and retrieve nearby wireless access-point metadata,\nincluding SSIDs, BSSIDs, authentication and encryption modes, and\nsignal-strength information.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may disclose information about the wireless environment\nsurrounding the camera, allowing an attacker to learn elements of the local\nwireless topology."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "CWE-306 Missing authentication for critical function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:41:49.774Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5321/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 \u0026 C200",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-78577",
"datePublished": "2026-10-01T17:41:49.774Z",
"dateReserved": "2026-08-24T20:46:18.534Z",
"dateUpdated": "2026-10-01T18:08:59.956Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-9032 (GCVE-0-2026-9032)
Vulnerability from cvelistv5 – Published: 2026-10-01 17:41 – Updated: 2026-10-01 17:41
VLAI
EPSS
VEX
Title
Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerability in TP-Link Tapo C120 & C200
Summary
Tapo C120 v1 and C200 v5
contain a NULL pointer dereference in the HTTPS onboarding connect request parser. The interface is reachable without
authentication after initial setup and does not validate that a password field
is present for certain authentication and encryption parameter combinations,
allowing a malformed request from the same local network to crash the HTTPS service
Successful exploitation may
temporarily make HTTPS management functions unavailable. Repeated malformed
requests may sustain the denial-of-service condition, and recovery may in some
cases require a device reboot.
Severity
CWE
- CWE-476 - NULL pointer dereference
Assigner
References
5 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C200 V5 |
Affected:
0 , < V5_1.4.6 Build 260709 Rel.27675n
(custom)
|
|
| TP-Link Systems Inc. | Tapo C120 V1 |
Affected:
0 , < V1_1.9.4 Build 260813 Rel.79754n
(custom)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Tapo C200 V5",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Tapo C120 V1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eTapo C120 v1 and C200 v5\ncontain a NULL pointer dereference in the HTTPS onboarding connect request parser.\u0026nbsp; The interface is reachable without\nauthentication after initial setup and does not validate that a password field\nis present for certain authentication and encryption parameter combinations,\nallowing a malformed request from the same local network to crash the HTTPS service\n\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003e\u003cb\u003e\u0026nbsp;\u003c/b\u003eSuccessful exploitation may\ntemporarily make HTTPS management functions unavailable. Repeated malformed\nrequests may sustain the denial-of-service condition, and recovery may in some\ncases require a device reboot.\u003c/p\u003e"
}
],
"value": "Tapo C120 v1 and C200 v5\ncontain a NULL pointer dereference in the HTTPS onboarding connect request parser.\u00a0 The interface is reachable without\nauthentication after initial setup and does not validate that a password field\nis present for certain authentication and encryption parameter combinations,\nallowing a malformed request from the same local network to crash the HTTPS service\n\n\n\n\n\n\n\n\n\n\n\u00a0Successful exploitation may\ntemporarily make HTTPS management functions unavailable. Repeated malformed\nrequests may sustain the denial-of-service condition, and recovery may in some\ncases require a device reboot."
}
],
"impacts": [
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Overflow Buffers"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-476",
"description": "CWE-476 NULL pointer dereference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:41:31.004Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5321/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerability in TP-Link Tapo C120 \u0026 C200",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-9032",
"datePublished": "2026-10-01T17:41:31.004Z",
"dateReserved": "2026-05-19T16:30:36.090Z",
"dateUpdated": "2026-10-01T17:41:31.004Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102294 (GCVE-0-2026-102294)
Vulnerability from cvelistv5 – Published: 2026-10-01 17:30 – Updated: 2026-10-02 03:55
VLAI
EPSS
VEX
Title
Authenticated OS Command Injection in TL-WR841N IPv6 WAN Configuration
Summary
TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands.
Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 00:00 UTC
CWE
- CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/tl-wr… | patch |
| https://www.tp-link.com/us/support/download/tl-wr… | patch |
| https://www.tp-link.com/us/support/faq/5320/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link System Inc. | TL-WR841N v14 |
Affected:
0 , < 4.19 Build 260821 (EN)
(custom)
Affected: 0 , < 4.19 Build 260820 (US) (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102294",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T03:55:34.100Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "TL-WR841N v14",
"vendor": "TP-Link System Inc.",
"versions": [
{
"lessThan": "4.19 Build 260821 (EN)",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "4.19 Build 260820 (US)",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Petar Knezevic \u003cp.knezevic@gmx.ch\u003e"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003eTP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands.\u0026nbsp;\u003c/div\u003e\u003cdiv\u003eSuccessful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.\u003c/div\u003e\n\u003cbr\u003e"
}
],
"value": "TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands.\u00a0\n\nSuccessful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation."
}
],
"impacts": [
{
"capecId": "CAPEC-88",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-88 OS Command Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:30:19.919Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-wr841n/v14/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tl-wr841n/v14/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5320/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Authenticated OS Command Injection in TL-WR841N IPv6 WAN Configuration",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-102294",
"datePublished": "2026-10-01T17:30:19.919Z",
"dateReserved": "2026-09-28T20:55:19.080Z",
"dateUpdated": "2026-10-02T03:55:34.100Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84941 (GCVE-0-2026-84941)
Vulnerability from cvelistv5 – Published: 2026-09-10 23:35 – Updated: 2026-09-11 13:16
VLAI
EPSS
VEX
Title
Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read
Summary
An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-11 13:10 UTC
CWE
- CWE-611 - Improper restriction of XML external entity reference
Assigner
References
5 references
Impacted products
9 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Omada Software Controller (Windows) |
Affected:
0 , < 6.2.14.11
(custom)
|
|
| TP-Link Systems Inc. | Omada Software Controller (Linux) |
Affected:
0 , < 6.2.14.11
(custom)
|
|
| TP-Link Systems Inc. | OC2000 v1 |
Affected:
0 , < 1.41.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC2000 v2 |
Affected:
0 , < 2.26.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC200 v3 |
Affected:
0 , < 3.3.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC220 v1 |
Affected:
0 , < 1.6.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC220 v2 |
Affected:
0 , < 2.5.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC300 v1 |
Affected:
0 , < 1.35.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC400 v1 |
Affected:
0 , < 1.13.11 Build 20260711
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-84941",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-11T13:10:27.244979Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T13:16:12.359Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "Omada Software Controller (Windows)",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "6.2.14.11",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "Omada Software Controller (Linux)",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "6.2.14.11",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC2000 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.41.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC2000 v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.26.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC200 v3",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "3.3.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC220 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.6.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC220 v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.5.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC300 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.35.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC400 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.13.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "erikdejong"
},
{
"lang": "en",
"type": "finder",
"value": "mattgsys"
},
{
"lang": "en",
"type": "finder",
"value": "eslam moneer (tohtmosiii)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003eAn information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.\u003c/div\u003e"
}
],
"value": "An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information."
}
],
"impacts": [
{
"capecId": "CAPEC-221",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-221 Data Serialization External Entities Blowup"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-611",
"description": "CWE-611 Improper restriction of XML external entity reference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T23:35:53.023Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://support.omadanetworks.com/en/download/software/omada-controller"
},
{
"tags": [
"patch"
],
"url": "https://support.omadanetworks.com/us/download/software/omada-controller"
},
{
"tags": [
"patch"
],
"url": "https://www.omadanetworks.com/en/support/download/"
},
{
"tags": [
"patch"
],
"url": "https://www.omadanetworks.com/us/support/download/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://support.omadanetworks.com/en/document/133722/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-84941",
"datePublished": "2026-09-10T23:35:53.023Z",
"dateReserved": "2026-09-02T16:45:11.015Z",
"dateUpdated": "2026-09-11T13:16:12.359Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-17176 (GCVE-0-2026-17176)
Vulnerability from cvelistv5 – Published: 2026-09-10 23:14 – Updated: 2026-10-01 17:55
VLAI
EPSS
VEX
Title
OS Command Injection Vulnerability in Deco Devices
Summary
An OS
command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an
adjacent network attacker to execute arbitrary commands with root privileges by
sending a crafted UDP packet.
Successful exploitation may lead to complete
device compromise, including unauthorized command execution, modification of
device settings, and loss of confidentiality, integrity, and availability
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-11 14:32 UTC
CWE
- CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
Assigner
References
4 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Deco BE11000 V2 |
Affected:
0 , < 1.3.5 Build 26071712
(custom)
|
|
| TP-Link Systems Inc. | Deco M9 Plus V2 |
Affected:
0 , < 1.9.2 Build 20260818
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-17176",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-11T14:32:22.502230Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T14:32:34.104Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"tddp"
],
"product": "Deco BE11000 V2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.3.5 Build 26071712",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"modules": [
"tddp"
],
"product": "Deco M9 Plus V2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.9.2 Build 20260818",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Isa Roovers"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn OS\ncommand injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an\nadjacent network attacker to execute arbitrary commands with root privileges by\nsending a crafted UDP packet.\u003c/p\u003e\n\nSuccessful exploitation may lead to complete\ndevice compromise, including unauthorized command execution, modification of\ndevice settings, and loss of confidentiality, integrity, and availability"
}
],
"value": "An OS\ncommand injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an\nadjacent network attacker to execute arbitrary commands with root privileges by\nsending a crafted UDP packet.\n\n\n\nSuccessful exploitation may lead to complete\ndevice compromise, including unauthorized command execution, modification of\ndevice settings, and loss of confidentiality, integrity, and availability"
}
],
"impacts": [
{
"capecId": "CAPEC-248",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-248 Command Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:55:21.166Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/deco-be11000/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/en/support/faq/5293/"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/deco-m9-plus/v2/"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/deco-m9-plus/v2/#Firmware"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "OS Command Injection Vulnerability in Deco Devices",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-17176",
"datePublished": "2026-09-10T23:14:33.974Z",
"dateReserved": "2026-07-24T18:24:49.819Z",
"dateUpdated": "2026-10-01T17:55:21.166Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76652 (GCVE-0-2026-76652)
Vulnerability from cvelistv5 – Published: 2026-09-10 20:12 – Updated: 2026-09-10 20:27
VLAI
EPSS
VEX
Title
Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600
Summary
An
authenticated directory traversal vulnerability in file upload functionality has
been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file
information, an authenticated remote attacker with access to the affected
upload functionality could upload a specially crafted file and cause it to be
written outside the intended directory.
Successful
exploitation could allow an authenticated remote attacker to write files to
unintended locations, potentially overwriting or modifying files
accessible to the affected service; arbitrary code execution has not
been demonstrated.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-10 20:26 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/tl-mr… | patch |
| https://www.tp-link.com/en/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5292/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v8 |
Affected:
0 , < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n
(custom)
|
|
| TP-Link Systems Inc. | Archer MR600 |
Affected:
v3 , < MR600(EU)_V3_1.4.0 Build 260827
(custom)
Affected: v5 , < MR600(EU)_V5_1.9.0 Build 260805 (custom) Affected: v2 , < MR600(EU)_V2_1.12.0 Build 2600826 (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76652",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T20:26:30.638965Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T20:27:00.302Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "TL-MR6400 v8",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "Archer MR600",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "MR600(EU)_V3_1.4.0 Build 260827",
"status": "affected",
"version": "v3",
"versionType": "custom"
},
{
"lessThan": "MR600(EU)_V5_1.9.0 Build 260805",
"status": "affected",
"version": "v5",
"versionType": "custom"
},
{
"lessThan": "MR600(EU)_V2_1.12.0 Build 2600826",
"status": "affected",
"version": "v2",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn\nauthenticated directory traversal vulnerability in file upload functionality has\nbeen identified in Archer MR600 (v2, v3 \u0026amp; v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file\ninformation, an authenticated remote attacker with access to the affected\nupload functionality could upload a specially crafted file and cause it to be\nwritten outside the intended directory. \u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation could allow an authenticated remote attacker to write files to\nunintended locations, potentially overwriting or\u0026nbsp;modifying\u0026nbsp;files\naccessible to the affected service; arbitrary code execution has not\nbeen\u0026nbsp;demonstrated.\u0026nbsp;\u003c/p\u003e"
}
],
"value": "An\nauthenticated directory traversal vulnerability in file upload functionality has\nbeen identified in Archer MR600 (v2, v3 \u0026 v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file\ninformation, an authenticated remote attacker with access to the affected\nupload functionality could upload a specially crafted file and cause it to be\nwritten outside the intended directory. \n\n\n\n\n\nSuccessful\nexploitation could allow an authenticated remote attacker to write files to\nunintended locations, potentially overwriting or\u00a0modifying\u00a0files\naccessible to the affected service; arbitrary code execution has not\nbeen\u00a0demonstrated."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T20:12:50.706Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5292/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-76652",
"datePublished": "2026-09-10T20:12:50.706Z",
"dateReserved": "2026-08-19T15:49:30.548Z",
"dateUpdated": "2026-09-10T20:27:00.302Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76653 (GCVE-0-2026-76653)
Vulnerability from cvelistv5 – Published: 2026-09-10 20:12 – Updated: 2026-09-10 20:27
VLAI
EPSS
VEX
Title
Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR600
Summary
A missing
authentication vulnerability in the VPN configuration management has been
identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker
may be able to access and modify VPN configuration information without valid
credentials.
Successful
exploitation may allow a remote unauthenticated attacker to disclose and modify
VPN configuration information.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-10 20:27 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/tl-mr… | patch |
| https://www.tp-link.com/en/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5292/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v8 |
Affected:
0 , < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n
(custom)
|
|
| TP-Link Systems Inc. | Archer MR600 |
Affected:
v3 , < MR600(EU)_V3_1.4.0 Build 260827
(custom)
Affected: v2 , < MR600(EU)_V2_1.12.0 Build 2600826 (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76653",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T20:27:12.333163Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T20:27:18.091Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "TL-MR6400 v8",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "Archer MR600",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "MR600(EU)_V3_1.4.0 Build 260827",
"status": "affected",
"version": "v3",
"versionType": "custom"
},
{
"lessThan": "MR600(EU)_V2_1.12.0 Build 2600826",
"status": "affected",
"version": "v2",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003e\u003cspan\u003eA missing\nauthentication vulnerability in the VPN configuration management has been\nidentified\u0026nbsp;\u003c/span\u003e\u003cspan\u003ein Archer MR600 (v2, v3 \u0026amp; v5) and TL-MR6400 v8\u003c/span\u003e\u003cspan\u003e\u0026nbsp;\u003c/span\u003e\u003cspan\u003edue to improper access control; a remote unauthenticated attacker\nmay be able to access and modify VPN configuration information without valid\ncredentials.\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful\nexploitation may allow a remote unauthenticated attacker to disclose and modify\nVPN configuration information.\u003c/p\u003e"
}
],
"value": "A missing\nauthentication vulnerability in the VPN configuration management has been\nidentified\u00a0in Archer MR600 (v2, v3 \u0026 v5) and TL-MR6400 v8\u00a0due to improper access control; a remote unauthenticated attacker\nmay be able to access and modify VPN configuration information without valid\ncredentials.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow a remote unauthenticated attacker to disclose and modify\nVPN configuration information."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-126",
"description": "CWE-126",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T20:12:43.207Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5292/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR600",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-76653",
"datePublished": "2026-09-10T20:12:43.207Z",
"dateReserved": "2026-08-19T15:49:30.548Z",
"dateUpdated": "2026-09-10T20:27:18.091Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-85384 (GCVE-0-2026-85384)
Vulnerability from cvelistv5 – Published: 2026-09-08 18:43 – Updated: 2026-09-10 03:57 Unsupported When Assigned
VLAI
EPSS
VEX
Title
Authenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration Import
Summary
A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.
Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-09 00:00 UTC
CWE
- CWE-121 - Stack-based buffer overflow
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | RE210 AC750 |
Affected:
0 , ≤ 3.14.2 Build 141218 Rel.36430n (EU)
(custom)
Affected: 0 , ≤ 3.14.2 Build 171205 Rel.71984n (US) (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-85384",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-09T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T03:57:38.353Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"/usr/bin/httpd"
],
"product": "RE210 AC750",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThanOrEqual": "3.14.2 Build 141218 Rel.36430n (EU)",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThanOrEqual": "3.14.2 Build 171205 Rel.71984n (US)",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Michael Ace Bengil (Archan6el)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003c/div\u003e\u003cdiv\u003e\u003ci\u003e\u003c/i\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eA stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the \u003c/span\u003e\u003ccode\u003esplitString\u003c/code\u003e\u003cspan\u003e function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003eSuccessful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.\u003c/div\u003e\u003c/div\u003e"
}
],
"value": "A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.\n\n\n\n\n\nSuccessful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability."
}
],
"impacts": [
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Overflow Buffers"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "CWE-121 Stack-based buffer overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T18:43:58.166Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"url": "https://www.tp-link.com/en/support/faq/3562/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"tags": [
"unsupported-when-assigned"
],
"title": "Authenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration Import",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-85384",
"datePublished": "2026-09-08T18:43:58.166Z",
"dateReserved": "2026-09-03T18:02:10.505Z",
"dateUpdated": "2026-09-10T03:57:38.353Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-81531 (GCVE-0-2026-81531)
Vulnerability from cvelistv5 – Published: 2026-09-08 16:53 – Updated: 2026-09-21 18:01
VLAI
EPSS
VEX
Title
Unauthenticated Account Information Disclosure in Multiple Omada Controllers
Summary
An information
disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization
remains accessible after completion and may disclose account-related
information to unauthenticated remote users.
Successful
exploitation may allow an attacker to remote query the affected endpoint that
may facilitate user enumeration and subsequent attacks targeting administrative
accounts.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-08 17:21 UTC
CWE
- CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://support.omadanetworks.com/us/download/sof… | patch |
| https://support.omadanetworks.com/us/document/133567/ | vendor-advisory |
| https://support.omadanetworks.com/en/download/sof… | patch |
Impacted products
8 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link System Inc. | Omada Software Controller |
Affected:
0 , < 6.3.0.45
(custom)
|
|
| TP-Link Systems Inc. | OC200 V1 |
Affected:
0 , < (UN)_V1_1.42.10 Build 20260825
(custom)
|
|
| TP Link Systems Inc. | OC200 v2 |
Affected:
0 , < (UN)_V2_2.27.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc | OC200 v3 |
Affected:
0 , < (UN)_V3_3.4.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc. | OC220 v1 |
Affected:
0 , < (UN)_V1_1.7.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc | OC220 v2 |
Affected:
0 , < (UN)_V2_2.6.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc. | OC300 v1 |
Affected:
0 , < (UN)_V1_1.36.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc. | OC400 v1 |
Affected:
0 , < (UN)_V1_1.14.10 Build 20260825
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-81531",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-08T17:21:39.911958Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T17:21:54.913Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Windows",
"Linux"
],
"product": "Omada Software Controller",
"vendor": "TP-Link System Inc.",
"versions": [
{
"lessThan": "6.3.0.45",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC200 V1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V1_1.42.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC200 v2",
"vendor": "TP Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V2_2.27.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC200 v3",
"vendor": "TP-Link Systems Inc",
"versions": [
{
"lessThan": "(UN)_V3_3.4.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC220 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V1_1.7.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC220 v2",
"vendor": "TP-Link Systems Inc",
"versions": [
{
"lessThan": "(UN)_V2_2.6.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC300 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V1_1.36.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC400 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V1_1.14.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Joshua Chan, GitHub: https://github.com/popcorn94, Twitter: popc0rn94"
},
{
"lang": "en",
"type": "finder",
"value": "eslam moneer (tohtmosiii)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn information\ndisclosure vulnerability has been identified in Omada Controller.\u0026nbsp; An API endpoint intended for Controller initialization\nremains accessible after completion and may disclose account-related\ninformation to unauthenticated remote users.\u0026nbsp;\n\u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation may allow an attacker to remote query the affected endpoint that\nmay facilitate user enumeration and subsequent attacks targeting administrative\naccounts.\u003c/p\u003e"
}
],
"value": "An information\ndisclosure vulnerability has been identified in Omada Controller.\u00a0 An API endpoint intended for Controller initialization\nremains accessible after completion and may disclose account-related\ninformation to unauthenticated remote users.\u00a0\n\n\n\n\n\n\nSuccessful\nexploitation may allow an attacker to remote query the affected endpoint that\nmay facilitate user enumeration and subsequent attacks targeting administrative\naccounts."
}
],
"impacts": [
{
"capecId": "CAPEC-118",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-118 Collect \u0026 Analyze Information"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T18:01:46.384Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://support.omadanetworks.com/us/download/software/omada-controller/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://support.omadanetworks.com/us/document/133567/"
},
{
"tags": [
"patch"
],
"url": "https://support.omadanetworks.com/en/download/software/omada-controller/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Account Information Disclosure in Multiple Omada Controllers",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-81531",
"datePublished": "2026-09-08T16:53:18.786Z",
"dateReserved": "2026-08-26T22:31:50.287Z",
"dateUpdated": "2026-09-21T18:01:46.384Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-18167 (GCVE-0-2026-18167)
Vulnerability from cvelistv5 – Published: 2026-09-03 22:24 – Updated: 2026-09-04 18:25
VLAI
EPSS
VEX
Title
Stack-based buffer overflow in TP-Link Archer AX55 v4
Summary
A
stack-based buffer overflow vulnerability exists in the EasyMesh module of
TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit
crafted input that causes the easymesh daemon to crash and may potentially
achieve remote code execution on the device.
Successful
exploitation may cause the EasyMesh daemon to crash and may potentially allow
remote code execution when Mesh mode is enabled. This
may result in high impact to the confidentiality, integrity, and availability
of the affected device.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-04 17:09 UTC
CWE
- CWE-121 - Stack-based buffer overflow
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5279/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Archer AX55 v4 |
Affected:
0 , < 1.2.1 Build 20260527
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-18167",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T17:09:09.470755Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T18:25:53.240Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"easymesh"
],
"product": "Archer AX55 v4",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.1 Build 20260527",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Tianchang Yang and Syed Rafiul Hussain (SyNSec Lab, Penn State University)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA\nstack-based buffer overflow vulnerability exists in the EasyMesh module of\nTP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit\ncrafted input that causes the easymesh daemon to crash and may potentially\nachieve remote code execution on the device.\u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation may cause the EasyMesh daemon to crash and may potentially allow\nremote code execution when Mesh mode is enabled. This\nmay result in high impact to the confidentiality, integrity, and availability\nof the affected device.\u003c/p\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e"
}
],
"value": "A\nstack-based buffer overflow vulnerability exists in the EasyMesh module of\nTP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit\ncrafted input that causes the easymesh daemon to crash and may potentially\nachieve remote code execution on the device.\n\n\n\n\n\nSuccessful\nexploitation may cause the EasyMesh daemon to crash and may potentially allow\nremote code execution when Mesh mode is enabled. This\nmay result in high impact to the confidentiality, integrity, and availability\nof the affected device."
}
],
"impacts": [
{
"capecId": "CAPEC-47",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-47 Buffer Overflow via Parameter Expansion"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "CWE-121 Stack-based buffer overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T22:24:57.369Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/archer-ax55/v4/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5279/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Stack-based buffer overflow in TP-Link Archer AX55 v4",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-18167",
"datePublished": "2026-09-03T22:24:57.369Z",
"dateReserved": "2026-07-28T20:48:04.039Z",
"dateUpdated": "2026-09-04T18:25:53.240Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-18330 (GCVE-0-2026-18330)
Vulnerability from cvelistv5 – Published: 2026-09-03 22:24 – Updated: 2026-09-04 18:25
VLAI
EPSS
VEX
Title
Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4
Summary
A hard-coded
cryptographic key vulnerability exists in the web module of TP-Link Archer
AX55 v4. A LAN attacker who captures an HTTP login session may use the known
shared RSA private key to decrypt the administrator password; the
weakened AES session key further reduces the effort required to
compromise session confidentiality.
Successful
exploitation may disclose the administrator password captured from an HTTP
login session and compromise session confidentiality.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-04 17:39 UTC
CWE
- CWE-321 - Use of hard-coded cryptographic key
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5279/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Archer AX55 v4 |
Affected:
0 , < 1.2.1 Build 20260527
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-18330",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T17:39:51.418332Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T18:25:58.339Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"web"
],
"product": "Archer AX55 v4",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.1 Build 20260527",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Tianchang Yang and Syed Rafiul Hussain (SyNSec Lab, Penn State University)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA hard-coded\ncryptographic key vulnerability exists in the\u0026nbsp;web module of TP-Link Archer\nAX55 v4. A LAN attacker who captures an HTTP login session may use the known\nshared RSA private key to decrypt the\u0026nbsp;administrator\u0026nbsp;password; the\nweakened AES session key further reduces the effort\u0026nbsp;required\u0026nbsp;to\ncompromise session confidentiality.\u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation may disclose the administrator password captured from an HTTP\nlogin session and compromise session confidentiality.\u0026nbsp;\u003c/p\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e"
}
],
"value": "A hard-coded\ncryptographic key vulnerability exists in the\u00a0web module of TP-Link Archer\nAX55 v4. A LAN attacker who captures an HTTP login session may use the known\nshared RSA private key to decrypt the\u00a0administrator\u00a0password; the\nweakened AES session key further reduces the effort\u00a0required\u00a0to\ncompromise session confidentiality.\n\n\n\n\n\nSuccessful\nexploitation may disclose the administrator password captured from an HTTP\nlogin session and compromise session confidentiality."
}
],
"impacts": [
{
"capecId": "CAPEC-117",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-117 Interception"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-321",
"description": "CWE-321 Use of hard-coded cryptographic key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T22:24:45.430Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/archer-ax55/v4/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5279/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-18330",
"datePublished": "2026-09-03T22:24:45.430Z",
"dateReserved": "2026-07-29T20:03:53.524Z",
"dateUpdated": "2026-09-04T18:25:58.339Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-75118 (GCVE-0-2026-75118)
Vulnerability from cvelistv5 – Published: 2026-08-28 20:31 – Updated: 2026-09-01 14:46
VLAI
EPSS
VEX
Title
http_gdpr_decrypt Pre-Authentication Stack-Based Buffer Overflow
Summary
A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds checking of encrypted requests to the /cgi/login endpoint. An adjacent unauthenticated attacker with access to the router's web management interface can trigger memory corruption and potentially achieve arbitrary code execution.
Successful exploitation can overwrite saved control-flow data on the httpd process stack prior to authentication, resulting in a service crash or potential arbitrary code execution in the context of the affected process.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-01 03:56 UTC
CWE
- CWE-121 - Stack-based buffer overflow
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/tl-mr… | patch |
| https://www.tp-link.com/en/support/faq/5271/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR100 v3.20 |
Affected:
0 , < (EU)_1.3.0 Build 260609
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-75118",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-01T03:56:22.838725Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-01T14:46:29.955Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"/usr/bin/httpd"
],
"product": "TL-MR100 v3.20",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(EU)_1.3.0 Build 260609",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Kylian Eury"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cdiv\u003eA pre-authentication stack-based buffer overflow vulnerability exists in the \u003ccode\u003ehttp_gdpr_decrypt\u003c/code\u003e function of TL-MR100 V3.20 due to insufficient bounds checking of encrypted requests to the \u003ccode\u003e/cgi/login\u003c/code\u003e endpoint. An adjacent unauthenticated attacker with access to the router\u0027s web management interface can trigger memory corruption and potentially achieve arbitrary code execution.\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\n\u003cdiv\u003eSuccessful exploitation can overwrite saved control-flow data on the \u003ccode\u003ehttpd\u003c/code\u003e process stack prior to authentication, resulting in a service crash or potential arbitrary code execution in the context of the affected process.\u003c/div\u003e"
}
],
"value": "A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds checking of encrypted requests to the /cgi/login endpoint. An adjacent unauthenticated attacker with access to the router\u0027s web management interface can trigger memory corruption and potentially achieve arbitrary code execution.\n\n\n\n\n\n\n\nSuccessful exploitation can overwrite saved control-flow data on the httpd process stack prior to authentication, resulting in a service crash or potential arbitrary code execution in the context of the affected process."
}
],
"impacts": [
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Overflow Buffers"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "CWE-121 Stack-based buffer overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-28T20:31:03.977Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-mr100/v3.20/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/en/support/faq/5271/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "http_gdpr_decrypt Pre-Authentication Stack-Based Buffer Overflow",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-75118",
"datePublished": "2026-08-28T20:31:03.977Z",
"dateReserved": "2026-08-17T18:18:43.498Z",
"dateUpdated": "2026-09-01T14:46:29.955Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76651 (GCVE-0-2026-76651)
Vulnerability from cvelistv5 – Published: 2026-08-28 20:19 – Updated: 2026-08-31 18:36
VLAI
EPSS
VEX
Title
Pre-Authentication Multipart Boundary Buffer Overflow in HTTP Service in TP-Link TL-WR841N
Summary
A buffer
overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing
multipart/form-data requests. Insufficient validation of an attacker-controlled
boundary parameter may allow a remote unauthenticated attacker to submit a
crafted request that corrupts memory by overwriting data beyond the bounds of
an internal buffer.
Successful
exploitation may result in modification or corruption of process memory,
potentially leading to undefined application behavior. Arbitrary code
execution, information disclosure, and denial-of-service conditions have not
been demonstrated.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-31 18:36 UTC
CWE
- CWE-120 - Buffer Copy without Checking Size of Input
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/tl-wr… | patch |
| https://www.tp-link.com/en/support/download/tl-wr… | patch |
| https://www.tp-link.com/us/support/faq/5270/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link System Inc. | TL-WR841N v14 |
Affected:
0 , < TL-WR841N(US)_V14_4.19 Build 260820 Rel.33478
(custom)
Affected: 0 , < TL-WR841N(EU)_V14_4.19 Build 260821 Rel.56588 (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76651",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-31T18:36:33.966883Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T18:36:46.288Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "TL-WR841N v14",
"vendor": "TP-Link System Inc.",
"versions": [
{
"lessThan": "TL-WR841N(US)_V14_4.19 Build 260820 Rel.33478",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "TL-WR841N(EU)_V14_4.19 Build 260821 Rel.56588",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003e\u003cspan\u003eA buffer\noverflow vulnerability exists in the embedded HTTP service\u0026nbsp;\u003c/span\u003e\u003cspan\u003ein TL-WR841N v14\u003c/span\u003e\u003cspan\u003e\u0026nbsp;\u003c/span\u003e\u003cspan\u003ewhen processing\nmultipart/form-data requests. Insufficient validation of an attacker-controlled\nboundary parameter may allow a remote unauthenticated attacker to submit a\ncrafted request that corrupts memory by overwriting data beyond the bounds of\nan internal buffer.\u003c/span\u003e\u003c/p\u003e\u003cdiv\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful\nexploitation may result in modification or corruption of process memory,\npotentially leading to undefined application behavior. Arbitrary code\nexecution, information disclosure, and denial-of-service conditions have not\nbeen demonstrated.\u003c/p\u003e\u003c/div\u003e"
}
],
"value": "A buffer\noverflow vulnerability exists in the embedded HTTP service\u00a0in TL-WR841N v14\u00a0when processing\nmultipart/form-data requests. Insufficient validation of an attacker-controlled\nboundary parameter may allow a remote unauthenticated attacker to submit a\ncrafted request that corrupts memory by overwriting data beyond the bounds of\nan internal buffer.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may result in modification or corruption of process memory,\npotentially leading to undefined application behavior. Arbitrary code\nexecution, information disclosure, and denial-of-service conditions have not\nbeen demonstrated."
}
],
"impacts": [
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Overflow Buffers"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-120",
"description": "CWE-120 Buffer Copy without Checking Size of Input",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-28T20:19:09.293Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tl-wr841n/v14/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-wr841n/v14/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5270/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Pre-Authentication Multipart Boundary Buffer Overflow in HTTP Service in TP-Link TL-WR841N",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-76651",
"datePublished": "2026-08-28T20:19:09.293Z",
"dateReserved": "2026-08-19T15:49:30.548Z",
"dateUpdated": "2026-08-31T18:36:46.288Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76650 (GCVE-0-2026-76650)
Vulnerability from cvelistv5 – Published: 2026-08-28 20:19 – Updated: 2026-08-31 18:37
VLAI
EPSS
VEX
Title
Pre-Authentication NULL Pointer Dereference in UPnP SOAP State Variable Query Processing in TP-Link TL-WR841N
Summary
A NULL
pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing
SOAP state variable query requests. A specially crafted SOAP query may trigger
unexpected termination or instability of the process hosting the UPnP service.
Successful
exploitation may result in a denial-of-service condition affecting UPnP
discovery, state query, or related management functionality until the affected
process is restarted or the device is rebooted.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-31 18:36 UTC
CWE
- CWE-476 - NULL pointer dereference
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/tl-wr… | patch |
| https://www.tp-link.com/en/support/download/tl-wr… | patch |
| https://www.tp-link.com/us/support/faq/5270/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link System Inc. | TL-WR841N v14 |
Affected:
0 , < TL-WR841N(US)_V14_4.19 Build 260820 Rel.33478
(custom)
Affected: 0 , < TL-WR841N(EU)_V14_4.19 Build 260821 Rel.56588 (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76650",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-31T18:36:59.443811Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T18:37:11.079Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "TL-WR841N v14",
"vendor": "TP-Link System Inc.",
"versions": [
{
"lessThan": "TL-WR841N(US)_V14_4.19 Build 260820 Rel.33478",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "TL-WR841N(EU)_V14_4.19 Build 260821 Rel.56588",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003e\u003cspan\u003eA NULL\npointer dereference vulnerability exists in\u0026nbsp;\u003c/span\u003e\u003cspan\u003eTL-WR841N v14\u003c/span\u003e\u003cspan\u003e\u0026nbsp;in\u003c/span\u003e\u003cspan\u003e\u0026nbsp;the UPnP service when processing\nSOAP state variable query requests. A specially crafted SOAP query may trigger\nunexpected termination or instability of the process hosting the UPnP service.\u003c/span\u003e\u003c/p\u003e\u003cdiv\u003e\n\n\u003cp\u003eSuccessful\nexploitation may result in a denial-of-service condition affecting UPnP\ndiscovery, state query, or related management functionality until the affected\nprocess is restarted or the device is rebooted.\u003c/p\u003e\u003c/div\u003e"
}
],
"value": "A NULL\npointer dereference vulnerability exists in\u00a0TL-WR841N v14\u00a0in\u00a0the UPnP service when processing\nSOAP state variable query requests. A specially crafted SOAP query may trigger\nunexpected termination or instability of the process hosting the UPnP service.\n\n\n\n\n\nSuccessful\nexploitation may result in a denial-of-service condition affecting UPnP\ndiscovery, state query, or related management functionality until the affected\nprocess is restarted or the device is rebooted."
}
],
"impacts": [
{
"capecId": "CAPEC-153",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-153 Input Data Manipulation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-476",
"description": "CWE-476 NULL pointer dereference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-28T20:19:03.475Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tl-wr841n/v14/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-wr841n/v14/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5270/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Pre-Authentication NULL Pointer Dereference in UPnP SOAP State Variable Query Processing in TP-Link TL-WR841N",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-76650",
"datePublished": "2026-08-28T20:19:03.475Z",
"dateReserved": "2026-08-19T15:49:30.548Z",
"dateUpdated": "2026-08-31T18:37:11.079Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76649 (GCVE-0-2026-76649)
Vulnerability from cvelistv5 – Published: 2026-08-28 20:18 – Updated: 2026-08-31 18:37
VLAI
EPSS
VEX
Title
Pre-Authentication NULL Pointer Dereference in UPnP SOAP Action Request Processing in TP-Link TL-WR841N
Summary
A NULL
pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action requests. A specially crafted SOAP action request containing unexpected XML content may cause the UPnP daemon to terminate unexpectedly.
Successful exploitation may result in a denial-of-service condition affecting UPnP functionality until the service is restarted or the device is rebooted.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-31 18:37 UTC
CWE
- CWE-476 - NULL pointer dereference
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/tl-wr… | patch |
| https://www.tp-link.com/en/support/download/tl-wr… | patch |
| https://www.tp-link.com/us/support/faq/5270/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link System Inc. | TL-WR841N v14 |
Affected:
0 , < TL-WR841N(US)_V14_4.19 Build 260820 Rel.33478
(custom)
Affected: 0 , < TL-WR841N(EU)_V14_4.19 Build 260821 Rel.56588 (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76649",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-31T18:37:22.157600Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T18:37:30.759Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "TL-WR841N v14",
"vendor": "TP-Link System Inc.",
"versions": [
{
"lessThan": "TL-WR841N(US)_V14_4.19 Build 260820 Rel.33478",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "TL-WR841N(EU)_V14_4.19 Build 260821 Rel.56588",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA NULL\npointer dereference vulnerability exists in TL-WR841N v14 in the UPnP\u0026nbsp;\u003cspan\u003eservice when processing SOAP action requests. A specially crafted SOAP action request containing unexpected XML content may cause the UPnP daemon to terminate unexpectedly.\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cdiv\u003eSuccessful exploitation may result in a denial-of-service condition affecting UPnP functionality until the service is restarted or the device is rebooted.\u003c/div\u003e"
}
],
"value": "A NULL\npointer dereference vulnerability exists in TL-WR841N v14 in the UPnP\u00a0service when processing SOAP action requests. A specially crafted SOAP action request containing unexpected XML content may cause the UPnP daemon to terminate unexpectedly.\n\n\n\n\n\n\n\nSuccessful exploitation may result in a denial-of-service condition affecting UPnP functionality until the service is restarted or the device is rebooted."
}
],
"impacts": [
{
"capecId": "CAPEC-153",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-153 Input Data Manipulation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-476",
"description": "CWE-476 NULL pointer dereference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-28T20:18:57.764Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tl-wr841n/v14/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-wr841n/v14/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5270/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Pre-Authentication NULL Pointer Dereference in UPnP SOAP Action Request Processing in TP-Link TL-WR841N",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-76649",
"datePublished": "2026-08-28T20:18:57.764Z",
"dateReserved": "2026-08-19T15:49:30.548Z",
"dateUpdated": "2026-08-31T18:37:30.759Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76784 (GCVE-0-2026-76784)
Vulnerability from cvelistv5 – Published: 2026-08-26 17:47 – Updated: 2026-08-26 18:50
VLAI
EPSS
VEX
Title
Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices
Summary
Multiple
TP-Link Kasa smart home devices contain insufficient cryptographic protections
in the local device communication protocol. An adjacent network attacker may
intercept, replay or forge locally exchanged control messages, potentially
resulting in unauthorized device control.
Successful
exploitation could allow an attacker to manipulate the operational state of an
affected device, resulting in unauthorized state changes, disruption of normal
device functionality or a denial-of-service condition.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-26 18:43 UTC
CWE
- CWE-325 - Missing Cryptographic Step
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/ | patch |
| https://www.tp-link.com/en/support/download/ | patch |
| https://www.tp-link.com/in/support/download/ | patch |
| https://www.tp-link.com/us/support/faq/5267/ | vendor-advisory |
Impacted products
20 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | HS103P3 / HS103P4 v5 |
Affected:
0 , < 1.1.3 Build 250908 Rel.112508
(custom)
|
|
| TP-Link Systems Inc. | EP10 |
Affected:
0 , < 1.1.1 Build 250908 Rel.112508
(custom)
|
|
| TP-Link Systems Inc. | EP25 V2 |
Affected:
0 , < 1.0.3 Build 240529 Rel.145252
(custom)
|
|
| TP-Link Systems Inc. | HS300 V2 |
Affected:
0 , < 1.1.2 Build 241220 Rel.171333
(custom)
|
|
| TP-Link Systems Inc. | KP303 V2 |
Affected:
0 , < 1.1.2 Build 241220 Rel.173321
(custom)
|
|
| TP-Link Systems Inc. | EP40A |
Affected:
0 , < 1.1.1 Build 250908 Rel.112526
(custom)
|
|
| TP-Link Systems Inc. | KP125MP2 / KP125MP4 |
Affected:
0 , < 1.2.5 Build 241213 Rel.172504
(custom)
|
|
| TP-Link Systems Inc. | KP115 |
Affected:
0 , < 1.1.1 Build 250908 Rel.112945
(custom)
|
|
| TP-Link Systems Inc. | KS225 |
Affected:
0 , < 1.1.1 Build 240626 Rel.175125
(custom)
|
|
| TP-Link Systems Inc. | EP40M |
Affected:
0 , < 1.1.0 Build 240415 Rel.171219
(custom)
|
|
| TP-Link Systems Inc. | KS205 |
Affected:
0 , < 1.1.1 Build 240724 Rel.105920
(custom)
|
|
| TP-Link Systems Inc. | KS240 |
Affected:
0 , < 1.0.6 Build 240122 Rel.160100
(custom)
|
|
| TP-Link Systems Inc. | ES20M |
Affected:
0 , < 1.1.6 Build 250522 Rel.210254
(custom)
|
|
| TP-Link Systems Inc. | KS220M |
Affected:
0 , < 1.1.6 Build 250522 Rel.210254
(custom)
|
|
| TP-Link Systems Inc. | KP200 V3 |
Affected:
0 , < 1.1.0 Build 250225 Rel.171724
(custom)
|
|
| TP-Link Systems Inc. | HS200 V5.26 |
Affected:
0 , < 1.0.3 Build 240723 Rel.192622
(custom)
|
|
| TP-Link Systems Inc. | HS220-LA(US) 6.6 / HS220-BL(US) 6.6 |
Affected:
0 , < 1.0.3 Build 240723 Rel.192630
(custom)
|
|
| TP-Link Systems Inc. | HS220 V3.26 |
Affected:
0 , < 1.1.1 Build 240802 Rel.094131
(custom)
|
|
| TP-Link Systems Inc. | HS220-LA(US) 4.6 / HS220-BL(US) 4.6 |
Affected:
0 , < 1.1.1 Build 240802 Rel.094142
(custom)
|
|
| TP-Link Systems Inc. | KL125 |
Affected:
0 , < 1.1.1 Build 260710 Rel.082646
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76784",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-26T18:43:28.394552Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T18:50:19.860Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HS103P3 / HS103P4 v5",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.3 Build 250908 Rel.112508",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EP10",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.1 Build 250908 Rel.112508",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EP25 V2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.0.3 Build 240529 Rel.145252",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HS300 V2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.2 Build 241220 Rel.171333",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "KP303 V2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.2 Build 241220 Rel.173321",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EP40A",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.1 Build 250908 Rel.112526",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "KP125MP2 / KP125MP4",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.5 Build 241213 Rel.172504",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "KP115",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.1 Build 250908 Rel.112945",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "KS225",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.1 Build 240626 Rel.175125",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EP40M",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.0 Build 240415 Rel.171219",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "KS205",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.1 Build 240724 Rel.105920",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "KS240",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.0.6 Build 240122 Rel.160100",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ES20M",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.6 Build 250522 Rel.210254",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "KS220M",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.6 Build 250522 Rel.210254",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "KP200 V3",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.0 Build 250225 Rel.171724",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HS200 V5.26",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.0.3 Build 240723 Rel.192622",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HS220-LA(US) 6.6 / HS220-BL(US) 6.6",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.0.3 Build 240723 Rel.192630",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HS220 V3.26",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.1 Build 240802 Rel.094131",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HS220-LA(US) 4.6 / HS220-BL(US) 4.6",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.1 Build 240802 Rel.094142",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "KL125",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.1 Build 260710 Rel.082646",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Priyanka Rushikesh Chaudhary (Research Scholar, CSIS Department, BITS Pilani, Hyderabad Campus, India), Rajib Ranjan Maiti (Associate Professor, CSIS Department, BITS Pilani, Hyderabad Campus, India)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMultiple\nTP-Link Kasa smart home devices contain insufficient cryptographic protections\nin the local device communication protocol. An adjacent network attacker may\nintercept, replay or forge locally exchanged control messages, potentially\nresulting in unauthorized device control. \u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful\nexploitation could allow an attacker to manipulate the operational state of an\naffected device, resulting in unauthorized state changes, disruption of normal\ndevice functionality or a denial-of-service condition.\u003c/p\u003e"
}
],
"value": "Multiple\nTP-Link Kasa smart home devices contain insufficient cryptographic protections\nin the local device communication protocol. An adjacent network attacker may\nintercept, replay or forge locally exchanged control messages, potentially\nresulting in unauthorized device control. \n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation could allow an attacker to manipulate the operational state of an\naffected device, resulting in unauthorized state changes, disruption of normal\ndevice functionality or a denial-of-service condition."
}
],
"impacts": [
{
"capecId": "CAPEC-594",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-594 Traffic Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-325",
"description": "CWE-325: Missing Cryptographic Step",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T17:47:54.278Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/in/support/download/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5267/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-76784",
"datePublished": "2026-08-26T17:47:54.278Z",
"dateReserved": "2026-08-19T17:32:21.874Z",
"dateUpdated": "2026-08-26T18:50:19.860Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-78541 (GCVE-0-2026-78541)
Vulnerability from cvelistv5 – Published: 2026-08-24 18:26 – Updated: 2026-08-25 03:56
VLAI
EPSS
VEX
Title
Command Injection in Parent Control of TP-Link Archer BE3600 v1
Summary
A stored OS
command injection vulnerability exists in the parent-control module of TP-Link
Archer BE3600 V1. An authenticated adjacent attacker with administrative access
may store a crafted profile name containing shell metacharacters, which is
later processed unsafely during daily cloud report generation and may result in
arbitrary command execution.
Successful
exploitation may allow command execution on the affected device with potential
impact to device confidentiality, integrity, and availability.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-24 00:00 UTC
CWE
- CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/arche… | patch |
| https://www.tp-link.com/en/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5264/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Archer BE3600 v1 |
Affected:
0 , < 1.2.6 Build 20260617
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-78541",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-24T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T03:56:57.446Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"parent-control"
],
"product": "Archer BE3600 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.6 Build 20260617",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Sungmin Kang (rauzn), JeroScope"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA stored OS\ncommand injection vulnerability exists in the parent-control module of TP-Link\nArcher BE3600 V1. An authenticated adjacent attacker with administrative access\nmay store a crafted profile name containing shell metacharacters, which is\nlater processed unsafely during daily cloud report generation and may result in\narbitrary command execution.\u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation may allow command execution on the affected device with potential\nimpact to device confidentiality, integrity, and availability.\u003c/p\u003e"
}
],
"value": "A stored OS\ncommand injection vulnerability exists in the parent-control module of TP-Link\nArcher BE3600 V1. An authenticated adjacent attacker with administrative access\nmay store a crafted profile name containing shell metacharacters, which is\nlater processed unsafely during daily cloud report generation and may result in\narbitrary command execution.\n\n\n\n\n\nSuccessful\nexploitation may allow command execution on the affected device with potential\nimpact to device confidentiality, integrity, and availability."
}
],
"impacts": [
{
"capecId": "CAPEC-248",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-248 Command Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-24T18:26:11.670Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/archer-be3600/v1.26/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-be3600/v1/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5264/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Command Injection in Parent Control of TP-Link Archer BE3600 v1",
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-78541",
"datePublished": "2026-08-24T18:26:11.670Z",
"dateReserved": "2026-08-24T17:49:50.653Z",
"dateUpdated": "2026-08-25T03:56:57.446Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-16348 (GCVE-0-2026-16348)
Vulnerability from cvelistv5 – Published: 2026-08-24 17:25 – Updated: 2026-08-25 03:56
VLAI
EPSS
VEX
Title
Command Injection Vulnerability in VPN connection of Archer BE800
Summary
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.
Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-24 00:00 UTC
CWE
- CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/arche… | patch |
| https://www.tp-link.com/en/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5264/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Archer BE800 v1 |
Affected:
0 , < 1.4.2 Build 260708
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-16348",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-24T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T03:56:53.071Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"vpn connection"
],
"product": "Archer BE800 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.4.2 Build 260708",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Sean Lagan, UploadSecurity"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cdiv\u003eAn authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.\u0026nbsp;\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eSuccessful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.\u003c/div\u003e\u003c/div\u003e"
}
],
"value": "An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.\u00a0\n\n\n\n\nSuccessful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices."
}
],
"impacts": [
{
"capecId": "CAPEC-248",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-248 Command Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-24T17:25:46.598Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/archer-be800/v1/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-be800/v1/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5264/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Command Injection Vulnerability in VPN connection of Archer BE800",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-16348",
"datePublished": "2026-08-24T17:25:46.598Z",
"dateReserved": "2026-07-20T21:48:41.382Z",
"dateUpdated": "2026-08-25T03:56:53.071Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-9254 (GCVE-0-2026-9254)
Vulnerability from cvelistv5 – Published: 2026-08-24 17:25 – Updated: 2026-08-25 03:56
VLAI
EPSS
VEX
Title
Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices
Summary
An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges.
Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-24 00:00 UTC
CWE
- CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
Assigner
References
8 references
Impacted products
3 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Archer BE800 V1 |
Affected:
0 , < 1.4.2 Build 260708
(custom)
|
|
| TP-Link Systems Inc. | Archer BE3600 V1 |
Affected:
0 , < 1.2.6 Build 20260617
(custom)
|
|
| TP-Link Systems Inc. | Archer AX75 V1 |
Affected:
0 , < 1.1.6 Build 260716
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-9254",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-24T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T03:56:51.934Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"parent control"
],
"product": "Archer BE800 V1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.4.2 Build 260708",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"modules": [
"parent control"
],
"product": "Archer BE3600 V1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.6 Build 20260617",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"modules": [
"parent control"
],
"product": "Archer AX75 V1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.6 Build 260716",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Sean Lagan, UploadSecurity"
},
{
"lang": "en",
"type": "finder",
"value": "Sungmin Kang (rauzn), JeroScope"
},
{
"lang": "en",
"type": "finder",
"value": "Sergio Medeiros (grumpz)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003eAn unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges.\u003c/div\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e\u003cdiv\u003eSuccessful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.\u003c/div\u003e"
}
],
"value": "An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges.\n\n\n\n\n\n\nSuccessful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic."
}
],
"impacts": [
{
"capecId": "CAPEC-248",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-248 Command Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-24T17:25:30.486Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-be800/v1/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/archer-be800/v1/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-be3600/v1/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/archer-be3600/v1/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/kr/support/download/archer-be3600/v1/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-ax75/v1/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/archer-ax75/v1/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5264/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices",
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-9254",
"datePublished": "2026-08-24T17:25:30.486Z",
"dateReserved": "2026-05-21T20:23:27.422Z",
"dateUpdated": "2026-08-25T03:56:51.934Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-15469 (GCVE-0-2026-15469)
Vulnerability from cvelistv5 – Published: 2026-08-24 16:32 – Updated: 2026-08-24 18:00
VLAI
EPSS
VEX
Title
Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800
Summary
The use of
hard-coded cryptographic key vulnerability has been identified in the mesh
functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6.
A shared RSA-512 mesh group private key is present in the affected
firmware and is used by the mesh protocol for node authentication. An attacker who obtains the firmware image
and has local network access may be able to authenticate as a mesh node without
possessing a device-specific credential.
Successful
exploitation may allow an unauthenticated adjacent attacker to impersonate a
trusted mesh node and bypass mesh node authentication, which may permit unauthorized
changes to device or mesh configuration, affecting confidentiality, integrity
and availability.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-24 17:25 UTC
CWE
- CWE-321 - Use of hard-coded cryptographic key
Assigner
References
5 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Deco XE75 v3 / XE5300 v3.6/ WE10800 v3.6 |
Affected:
0 , < 1.5.0 Build 20260603
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-15469",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-24T17:25:18.245788Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-24T17:25:22.871Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"mesh"
],
"product": "Deco XE75 v3 / XE5300 v3.6/ WE10800 v3.6",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.5.0 Build 20260603",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Junsung Ahn"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe use of\nhard-coded cryptographic key vulnerability has been identified in the mesh\nfunctionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6.\u0026nbsp;\nA shared RSA-512 mesh group private key is present in the affected\nfirmware and is used by the mesh protocol for node authentication.\u0026nbsp; An attacker who obtains the firmware image\nand has local network access may be able to authenticate as a mesh node without\npossessing a device-specific credential.\u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation may allow an unauthenticated adjacent attacker to impersonate a\ntrusted mesh node and bypass mesh node authentication, which may permit unauthorized\nchanges to device or mesh configuration, affecting confidentiality, integrity\nand availability.\u003c/p\u003e"
}
],
"value": "The use of\nhard-coded cryptographic key vulnerability has been identified in the mesh\nfunctionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6.\u00a0\nA shared RSA-512 mesh group private key is present in the affected\nfirmware and is used by the mesh protocol for node authentication.\u00a0 An attacker who obtains the firmware image\nand has local network access may be able to authenticate as a mesh node without\npossessing a device-specific credential.\n\n\n\n\n\nSuccessful\nexploitation may allow an unauthenticated adjacent attacker to impersonate a\ntrusted mesh node and bypass mesh node authentication, which may permit unauthorized\nchanges to device or mesh configuration, affecting confidentiality, integrity\nand availability."
}
],
"impacts": [
{
"capecId": "CAPEC-115",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-115 Authentication Bypass"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-321",
"description": "CWE-321 Use of hard-coded cryptographic key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-24T18:00:49.583Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/deco-xe75/v3.60/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/deco-xe75/v3.60/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/deco-xe5300/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/deco-we10800/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5263/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800",
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-15469",
"datePublished": "2026-08-24T16:32:12.573Z",
"dateReserved": "2026-07-10T22:04:23.852Z",
"dateUpdated": "2026-08-24T18:00:49.583Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-17252 (GCVE-0-2026-17252)
Vulnerability from cvelistv5 – Published: 2026-08-21 17:16 – Updated: 2026-09-03 23:30
VLAI
EPSS
VEX
Title
Unauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based Out-of-Bounds Write Vulnerability in TL-MR6400 Web Management Interface
Summary
A
stack-based out-of-bounds write vulnerability exists in the login request
handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability
by sending a specially crafted malformed HTTP request.
Successful
exploitation may cause the web service process to crash, resulting in a
denial-of-service condition and temporary loss of access to the router's web
management interface.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-21 17:38 UTC
CWE
- CWE-787 - Out-of-bounds write
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/tl-mr… | patch |
| https://www.tp-link.com/tw/support/download/tl-mr… | patch |
| https://www.tp-link.com/us/support/faq/5259/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v7.0 |
Affected:
0 , < 1.9.0 Build 260714
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-17252",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-21T17:38:28.929657Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T17:38:36.456Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "TL-MR6400 v7.0",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.9.0 Build 260714",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Fabian Weber from CODE WHITE GmbH"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA\nstack-based out-of-bounds write vulnerability exists in the login request\nhandling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability\nby sending a specially crafted malformed HTTP request. \u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation may cause the web service process to crash, resulting in a\ndenial-of-service condition and temporary loss of access to the router\u0027s web\nmanagement interface.\u003c/p\u003e"
}
],
"value": "A\nstack-based out-of-bounds write vulnerability exists in the login request\nhandling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability\nby sending a specially crafted malformed HTTP request. \n\n\n\n\n\nSuccessful\nexploitation may cause the web service process to crash, resulting in a\ndenial-of-service condition and temporary loss of access to the router\u0027s web\nmanagement interface."
}
],
"impacts": [
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Overflow Buffers"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-787",
"description": "CWE-787 Out-of-bounds write",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T23:30:17.745Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-mr6400/v7/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/tw/support/download/tl-mr6400/v7/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5259/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based Out-of-Bounds Write Vulnerability in TL-MR6400 Web Management Interface",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-17252",
"datePublished": "2026-08-21T17:16:51.552Z",
"dateReserved": "2026-07-24T22:03:13.178Z",
"dateUpdated": "2026-09-03T23:30:17.745Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-17251 (GCVE-0-2026-17251)
Vulnerability from cvelistv5 – Published: 2026-08-21 17:16 – Updated: 2026-08-21 17:40
VLAI
EPSS
VEX
Title
Unauthenticated Denial of Service via Null Pointer Dereference in HTTP Request Parsing
Summary
A NULL
pointer dereference vulnerability exists in the HTTP request parsing
functionality of
TL-MR6400 v7. An unauthenticated remote attacker can
trigger the vulnerability by sending a specially crafted HTTP request
containing a malformed session cookie header.
Successful
exploitation may cause the HTTP service process to crash, resulting in a
denial-of-service condition and temporary loss of management or CGI
functionality until service recovery.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-21 17:40 UTC
CWE
- CWE-476 - NULL pointer dereference
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/tl-mr… | patch |
| https://www.tp-link.com/tw/support/download/tl-mr… | patch |
| https://www.tp-link.com/us/support/faq/5259/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v7.0 |
Affected:
0 , < 1.9.0 Build 260714
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-17251",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-21T17:40:25.485077Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T17:40:36.098Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "TL-MR6400 v7.0",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.9.0 Build 260714",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Rui Cheng Yu (Hina)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA NULL\npointer dereference vulnerability exists in the HTTP request parsing\nfunctionality of\u0026nbsp;\nTL-MR6400 v7. An unauthenticated remote attacker can\ntrigger the vulnerability by sending a specially crafted HTTP request\ncontaining a malformed session cookie header. \u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation may cause the HTTP service process to crash, resulting in a\ndenial-of-service condition and temporary loss of management or CGI\nfunctionality until service recovery.\u003c/p\u003e"
}
],
"value": "A NULL\npointer dereference vulnerability exists in the HTTP request parsing\nfunctionality of\u00a0\nTL-MR6400 v7. An unauthenticated remote attacker can\ntrigger the vulnerability by sending a specially crafted HTTP request\ncontaining a malformed session cookie header. \n\n\n\n\n\nSuccessful\nexploitation may cause the HTTP service process to crash, resulting in a\ndenial-of-service condition and temporary loss of management or CGI\nfunctionality until service recovery."
}
],
"impacts": [
{
"capecId": "CAPEC-135",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-135 Format String Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-476",
"description": "CWE-476 NULL pointer dereference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T17:16:45.791Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-mr6400/v7/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/tw/support/download/tl-mr6400/v7/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5259/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Denial of Service via Null Pointer Dereference in HTTP Request Parsing",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-17251",
"datePublished": "2026-08-21T17:16:45.791Z",
"dateReserved": "2026-07-24T22:03:11.872Z",
"dateUpdated": "2026-08-21T17:40:36.098Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-17250 (GCVE-0-2026-17250)
Vulnerability from cvelistv5 – Published: 2026-08-21 17:16 – Updated: 2026-08-25 03:56
VLAI
EPSS
VEX
Title
Authenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update Handling
Summary
A
stack-based buffer overflow vulnerability exists in the firmware update
functionality of TL-MR6400 v7 due to unsafe processing of
attacker-controlled metadata within a firmware image.
Successful
exploitation may allow an authenticated attacker to trigger memory corruption
and execute arbitrary code on the affected device.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-24 00:00 UTC
CWE
- CWE-121 - Stack-based buffer overflow
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/tl-mr… | patch |
| https://www.tp-link.com/tw/support/download/tl-mr… | patch |
| https://www.tp-link.com/us/support/faq/5259/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v7.0 |
Affected:
0 , < 1.9.0 Build 260714
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-17250",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-24T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T03:56:42.953Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "TL-MR6400 v7.0",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.9.0 Build 260714",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Rui Cheng Yu (Hina)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA\nstack-based buffer overflow vulnerability exists in the firmware update\nfunctionality of TL-MR6400 v7 due to unsafe processing of\nattacker-controlled metadata within a firmware image. \u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation may allow an authenticated attacker to trigger memory corruption\nand execute arbitrary code on the affected device.\u003c/p\u003e"
}
],
"value": "A\nstack-based buffer overflow vulnerability exists in the firmware update\nfunctionality of TL-MR6400 v7 due to unsafe processing of\nattacker-controlled metadata within a firmware image. \n\n\n\n\n\nSuccessful\nexploitation may allow an authenticated attacker to trigger memory corruption\nand execute arbitrary code on the affected device."
}
],
"impacts": [
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Overflow Buffers"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "CWE-121 Stack-based buffer overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T17:16:38.888Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-mr6400/v7/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/tw/support/download/tl-mr6400/v7/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5259/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Authenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update Handling",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-17250",
"datePublished": "2026-08-21T17:16:38.888Z",
"dateReserved": "2026-07-24T22:03:10.608Z",
"dateUpdated": "2026-08-25T03:56:42.953Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-19683 (GCVE-0-2026-19683)
Vulnerability from cvelistv5 – Published: 2026-08-20 18:32 – Updated: 2026-08-20 18:58
VLAI
EPSS
VEX
Title
Unencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada Gateways
Summary
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path.
Successful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-20 18:55 UTC
CWE
- CWE-319 - Cleartext transmission of sensitive information
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.omadanetworks.com/en/support/download/ | patch |
| https://www.omadanetworks.com/us/support/download/ | patch |
| https://www.tp-link.com/us/support/faq/5256/ | vendor-advisory |
Impacted products
19 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | ER7212PC v2 |
Affected:
0 , < 2.4.3 Build 20260722 Rel.40250
(custom)
|
|
| TP-Link Systems Inc. | ER605 v2 |
Affected:
0 , < 2.4.4 Build 20260630 Rel.14398
(custom)
|
|
| TP-Link Systems Inc. | ER7206 v2 |
Affected:
0 , < 2.3.5 Build 20260625 Rel.43136
(custom)
|
|
| TP-Link Systems Inc | ER7406 v1 |
Affected:
0 , < 1.3.4 Build 20260625 Rel.43136
(custom)
|
|
| TP-Link Systems Inc. | ER707-M2 v1 |
Affected:
0 , < 1.4.4 Build 20260625 Rel.43063
(custom)
|
|
| TP-Link Systems Inc | ER7412-M2 v1 |
Affected:
0 , < 1.2.0 Build 20260630 Rel.82947
(custom)
|
|
| TP-Link Systems Inc. | ER8411 v1 |
Affected:
0 , < 1.4.1 Build 20260708 Rel.64832
(custom)
|
|
| TP-Link Systems Inc. | ER706W v1 |
Affected:
0 , < 1.2.11 Build 20260723 Rel.41567
(custom)
|
|
| TP-Link Systems Inc. | v1 |
Affected:
0 , < 1.2.6 Build 20260723 Rel.41321
(custom)
|
|
| TP-Link Systems Inc. | ER706W-4G v2 |
Affected:
0 , < 2.1.11 Build 20260723 Rel.41624
(custom)
|
|
| TP-Link Systems Inc. | ER706WP-4G v1 |
Affected:
0 , < 1.1.11 Build 20260723 Rel.41624
(custom)
|
|
| TP-Link Systems Inc. | ER703WP-4G-Outdoor v1 |
Affected:
0 , < 1.1.7 Build 20260723 Rel.41712
(custom)
|
|
| TP-Link Systems Inc. | DR3220v-4G v1 |
Affected:
0 , < 1.2.0 Build 20260630 Rel.82652
(custom)
|
|
| TP-Link Systems Inc. | DR3650v v1 |
Affected:
0 , < 1.2.0 Build 20260630 Rel.83311
(custom)
|
|
| TP-Link Systems Inc. | DR3650v-4G v1 |
Affected:
0 , < 1.2.0 Build 20260630 Rel.83347
(custom)
|
|
| TP-Link Systems Inc. | ER603WP-4G-Outdoor v1 |
Affected:
0 , < 1.0.2 Build 20260723 Rel.43271
(custom)
|
|
| TP-Link Systems Inc. | DR3150 v1 |
Affected:
0 , < 1.0.1 Build 20260722 Rel.16854
(custom)
|
|
| TP-Link Systems Inc. | ER701-5G-Outdoor v1 |
Affected:
0 , < 1.0.3 Build 20260723 Rel.40931
(custom)
|
|
| TP-Link Systems Inc. | ER605W v2 |
Affected:
0 , < 2.0.4 Build 20260723 Rel.43763
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-19683",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-20T18:55:44.295305Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-20T18:58:42.948Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ER7212PC v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.4.3 Build 20260722 Rel.40250",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER605 v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.4.4 Build 20260630 Rel.14398",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER7206 v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.3.5 Build 20260625 Rel.43136",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER7406 v1",
"vendor": "TP-Link Systems Inc",
"versions": [
{
"lessThan": "1.3.4 Build 20260625 Rel.43136",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER707-M2 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.4.4 Build 20260625 Rel.43063",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER7412-M2 v1",
"vendor": "TP-Link Systems Inc",
"versions": [
{
"lessThan": "1.2.0 Build 20260630 Rel.82947",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER8411 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.4.1 Build 20260708 Rel.64832",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER706W v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.11 Build 20260723 Rel.41567",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.6 Build 20260723 Rel.41321",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER706W-4G v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.1.11 Build 20260723 Rel.41624",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER706WP-4G v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.11 Build 20260723 Rel.41624",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER703WP-4G-Outdoor v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.7 Build 20260723 Rel.41712",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "DR3220v-4G v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.0 Build 20260630 Rel.82652",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "DR3650v v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.0 Build 20260630 Rel.83311",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "DR3650v-4G v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.0 Build 20260630 Rel.83347",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER603WP-4G-Outdoor v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.0.2 Build 20260723 Rel.43271",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "DR3150 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.0.1 Build 20260722 Rel.16854",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER701-5G-Outdoor v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.0.3 Build 20260723 Rel.40931",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER605W v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.0.4 Build 20260723 Rel.43763",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cp\u003eA vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can\u0026nbsp;observe\u0026nbsp;or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path.\u0026nbsp;\u003c/p\u003e\u003c/div\u003e\u003cdiv\u003e\u003cp\u003eSuccessful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment.\u003c/p\u003e\u003c/div\u003e"
}
],
"value": "A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can\u00a0observe\u00a0or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path.\u00a0\n\n\n\n\n\nSuccessful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment."
}
],
"impacts": [
{
"capecId": "CAPEC-158",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-158 Sniffing Network Traffic"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-319",
"description": "CWE-319 Cleartext transmission of sensitive information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-20T18:32:27.650Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"name": "Omada Gateway Firmware Downloads (EN)",
"tags": [
"patch"
],
"url": "https://www.omadanetworks.com/en/support/download/"
},
{
"name": "Omada Gateway Firmware Downloads (US)",
"tags": [
"patch"
],
"url": "https://www.omadanetworks.com/us/support/download/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5256/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada Gateways",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-19683",
"datePublished": "2026-08-20T18:32:27.650Z",
"dateReserved": "2026-08-12T23:34:21.158Z",
"dateUpdated": "2026-08-20T18:58:42.948Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-19586 (GCVE-0-2026-19586)
Vulnerability from cvelistv5 – Published: 2026-08-20 18:32 – Updated: 2026-08-28 16:10
VLAI
EPSS
VEX
Title
Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways
Summary
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.
Successful exploitation may allow arbitrary command execution, potentially
leading to full compromise of the affected device.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-20 00:00 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://www.omadanetworks.com/en/support/download/ | patch |
| https://www.omadanetworks.com/us/support/download/ | patch |
| https://www.tp-link.com/us/support/faq/5256/ | vendor-advisory |
| https://mattg.systems/posts/cve-2026-19586/ | third-party-advisory |
Impacted products
19 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | ER7212PC v2 |
Affected:
0 , < 2.4.3 Build 20260722 Rel.40250
(custom)
|
|
| TP-Link Systems Inc. | ER605 v2 |
Affected:
0 , < 2.4.4 Build 20260630 Rel.14398
(custom)
|
|
| TP-Link Systems Inc. | ER7206 v2 |
Affected:
0 , < 2.3.5 Build 20260625 Rel.43136
(custom)
|
|
| TP-Link Systems Inc | ER7406 v1 |
Affected:
0 , < 1.3.4 Build 20260625 Rel.43136
(custom)
|
|
| TP-Link Systems Inc. | ER707-M2 v1 |
Affected:
0 , < 1.4.4 Build 20260625 Rel.43063
(custom)
|
|
| TP-Link Systems Inc | ER7412-M2 v1 |
Affected:
0 , < 1.2.0 Build 20260630 Rel.82947
(custom)
|
|
| TP-Link Systems Inc. | ER8411 v1 |
Affected:
0 , < 1.4.1 Build 20260708 Rel.64832
(custom)
|
|
| TP-Link Systems Inc. | ER706W v1 |
Affected:
0 , < 1.2.11 Build 20260723 Rel.41567
(custom)
|
|
| TP-Link Systems Inc. | v1 |
Affected:
0 , < 1.2.6 Build 20260723 Rel.41321
(custom)
|
|
| TP-Link Systems Inc. | ER706W-4G v2 |
Affected:
0 , < 2.1.11 Build 20260723 Rel.41624
(custom)
|
|
| TP-Link Systems Inc. | ER706WP-4G v1 |
Affected:
0 , < 1.1.11 Build 20260723 Rel.41624
(custom)
|
|
| TP-Link Systems Inc. | ER703WP-4G-Outdoor v1 |
Affected:
0 , < 1.1.7 Build 20260723 Rel.41712
(custom)
|
|
| TP-Link Systems Inc. | DR3220v-4G v1 |
Affected:
0 , < 1.2.0 Build 20260630 Rel.82652
(custom)
|
|
| TP-Link Systems Inc. | DR3650v v1 |
Affected:
0 , < 1.2.0 Build 20260630 Rel.83311
(custom)
|
|
| TP-Link Systems Inc. | DR3650v-4G v1 |
Affected:
0 , < 1.2.0 Build 20260630 Rel.83347
(custom)
|
|
| TP-Link Systems Inc. | ER603WP-4G-Outdoor v1 |
Affected:
0 , < 1.0.2 Build 20260723 Rel.43271
(custom)
|
|
| TP-Link Systems Inc. | DR3150 v1 |
Affected:
0 , < 1.0.1 Build 20260722 Rel.16854
(custom)
|
|
| TP-Link Systems Inc. | ER701-5G-Outdoor v1 |
Affected:
0 , < 1.0.3 Build 20260723 Rel.40931
(custom)
|
|
| TP-Link Systems Inc. | ER605W v2 |
Affected:
0 , < 2.0.4 Build 20260723 Rel.43763
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-19586",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-20T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T03:56:42.164Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ER7212PC v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.4.3 Build 20260722 Rel.40250",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER605 v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.4.4 Build 20260630 Rel.14398",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER7206 v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.3.5 Build 20260625 Rel.43136",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER7406 v1",
"vendor": "TP-Link Systems Inc",
"versions": [
{
"lessThan": "1.3.4 Build 20260625 Rel.43136",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER707-M2 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.4.4 Build 20260625 Rel.43063",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER7412-M2 v1",
"vendor": "TP-Link Systems Inc",
"versions": [
{
"lessThan": "1.2.0 Build 20260630 Rel.82947",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER8411 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.4.1 Build 20260708 Rel.64832",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER706W v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.11 Build 20260723 Rel.41567",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.6 Build 20260723 Rel.41321",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER706W-4G v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.1.11 Build 20260723 Rel.41624",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER706WP-4G v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.11 Build 20260723 Rel.41624",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER703WP-4G-Outdoor v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.7 Build 20260723 Rel.41712",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "DR3220v-4G v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.0 Build 20260630 Rel.82652",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "DR3650v v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.0 Build 20260630 Rel.83311",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "DR3650v-4G v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.0 Build 20260630 Rel.83347",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER603WP-4G-Outdoor v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.0.2 Build 20260723 Rel.43271",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "DR3150 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.0.1 Build 20260722 Rel.16854",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER701-5G-Outdoor v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.0.3 Build 20260723 Rel.40931",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ER605W v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.0.4 Build 20260723 Rel.43763",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Matt Graham (mattg.systems)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.\u0026nbsp;\u003c/p\u003e\u003cp\u003eSuccessful exploitation may allow arbitrary command execution,\u0026nbsp;\u003cspan\u003epotentially\nleading to full compromise of the affected device.\u003c/span\u003e\u003c/p\u003e"
}
],
"value": "A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.\u00a0\n\n\n\nSuccessful exploitation may allow arbitrary command execution,\u00a0potentially\nleading to full compromise of the affected device."
}
],
"impacts": [
{
"capecId": "CAPEC-88",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-88 OS Command Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-28T16:10:43.693Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"name": "Omada Gateway Firmware Downloads (EN)",
"tags": [
"patch"
],
"url": "https://www.omadanetworks.com/en/support/download/"
},
{
"name": "Omada Gateway Firmware Downloads (US)",
"tags": [
"patch"
],
"url": "https://www.omadanetworks.com/us/support/download/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5256/"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://mattg.systems/posts/cve-2026-19586/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-19586",
"datePublished": "2026-08-20T18:32:06.942Z",
"dateReserved": "2026-08-12T00:06:23.069Z",
"dateUpdated": "2026-08-28T16:10:43.693Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}