Search
Find a vulnerability
Search criteria
381 vulnerabilities by TP-Link Systems Inc.
CVE-2026-102370 (GCVE-0-2026-102370)
Vulnerability from nvd – Published: 2026-10-01 20:47 – Updated: 2026-10-01 21:01
VLAI
EPSS
VEX
Title
Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71
Summary
Kasa EC70 v4
and EC71 v4 do not logically disable the production debug interface at the
firmware or chip level and do not lock the bootloader. Although the debug traces are physically
severed during manufacturing, an attacker with physical access can restore the
connection, interrupt the boot process, and manipulate boot parameters to enter
a non-standard initialization path that exposes an unauthenticated root shell
during startup.
Successful exploitation may allow an
attacker with physical access to obtain root-level command access during device
startup, resulting in loss of confidentiality, integrity, and availability for
the affected device. Exploitation requires device disassembly, restoration of
the severed debug connection, and manipulation of the boot process.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 21:01 UTC
CWE
- CWE-1191 - On-Chip debug and test interface with improper access control
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/ec71/… | patch |
| https://www.tp-link.com/us/support/download/ec70/… | patch |
| https://www.tp-link.com/us/support/faq/5324/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Kasa EC70 V4 |
Affected:
0 , < 2.4.3 Build 20260902 rel.4511
(custom)
|
|
| TP-Link Systems Inc. | Kasa EC71 V4 |
Affected:
0 , < 2.4.3 Build 20260902 rel.4511
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102370",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T21:01:19.841347Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T21:01:44.613Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Kasa EC70 V4",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.4.3 Build 20260902 rel.4511",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Kasa EC71 V4",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.4.3 Build 20260902 rel.4511",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Christopher Childress"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eKasa EC70 v4\nand EC71 v4 do not logically disable the production debug interface at the\nfirmware or chip level and do not lock the bootloader.\u0026nbsp; Although the debug traces are physically\nsevered during manufacturing, an attacker with physical access can restore the\nconnection, interrupt the boot process, and manipulate boot parameters to enter\na non-standard initialization path that exposes an unauthenticated root shell\nduring startup.\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful exploitation may allow an\nattacker with physical access to obtain root-level command access during device\nstartup, resulting in loss of confidentiality, integrity, and availability for\nthe affected device. Exploitation requires device disassembly, restoration of\nthe severed debug connection, and manipulation of the boot process.\u003cb\u003e \u003c/b\u003e\u003c/p\u003e"
}
],
"value": "Kasa EC70 v4\nand EC71 v4 do not logically disable the production debug interface at the\nfirmware or chip level and do not lock the bootloader.\u00a0 Although the debug traces are physically\nsevered during manufacturing, an attacker with physical access can restore the\nconnection, interrupt the boot process, and manipulate boot parameters to enter\na non-standard initialization path that exposes an unauthenticated root shell\nduring startup.\n\n\n\n\n\n\n\n\n\nSuccessful exploitation may allow an\nattacker with physical access to obtain root-level command access during device\nstartup, resulting in loss of confidentiality, integrity, and availability for\nthe affected device. Exploitation requires device disassembly, restoration of\nthe severed debug connection, and manipulation of the boot process."
}
],
"impacts": [
{
"capecId": "CAPEC-116",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-116 Excavation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "PHYSICAL",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1191",
"description": "CWE-1191 On-Chip debug and test interface with improper access control",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T20:47:30.211Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/ec71/v4/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5324/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-102370",
"datePublished": "2026-10-01T20:47:30.211Z",
"dateReserved": "2026-09-28T23:32:02.361Z",
"dateUpdated": "2026-10-01T21:01:44.613Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-8618 (GCVE-0-2026-8618)
Vulnerability from nvd – Published: 2026-10-01 18:16 – Updated: 2026-10-01 18:36
VLAI
EPSS
VEX
Title
Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x91 on Deco M9 Plus
Summary
A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:35 UTC
CWE
- CWE-121 - Stack-based buffer overflow
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/deco-… | patch |
| https://www.tp-link.com/us/support/download/deco-… | patch |
| https://www.tp-link.com/us/support/faq/5322/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Deco M9 Plus V2 |
Affected:
0 , < 1.9.2 Build 20260818
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-8618",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:35:59.010450Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:36:18.919Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"tddp"
],
"product": "Deco M9 Plus V2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.9.2 Build 20260818",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Isa Roovers"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003eA stack-based buffer overflow vulnerability exists in the TDDPv2 service (\u003ccode\u003e/usr/bin/tddp\u003c/code\u003e) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype \u003ccode\u003e0x91\u003c/code\u003e handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets.\u003c/div\u003e"
}
],
"value": "A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets."
}
],
"impacts": [
{
"capecId": "CAPEC-123",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-123 Buffer Manipulation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "CWE-121 Stack-based buffer overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:16:32.107Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/deco-m9-plus/v2/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/deco-m9-plus/v2/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5322/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x91 on Deco M9 Plus",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-8618",
"datePublished": "2026-10-01T18:16:32.107Z",
"dateReserved": "2026-05-14T18:04:17.050Z",
"dateUpdated": "2026-10-01T18:36:18.919Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84682 (GCVE-0-2026-84682)
Vulnerability from nvd – Published: 2026-10-01 18:48 – Updated: 2026-10-02 03:55
VLAI
EPSS
VEX
Title
TDDPv2 setProductVer Command Injection in Archer AX90
Summary
A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot.
Successful exploitation may result in complete device compromise through arbitrary command execution with root privileges.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 00:00 UTC
CWE
- CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/arche… | patch |
| https://www.tp-link.com/en/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5323/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Archer AX90 v1 |
Affected:
0 , < 1.1.4 Build 20260927
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-84682",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T03:55:36.196Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"tddp"
],
"product": "Archer AX90 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.4 Build 20260927",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Can Oztas"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003eA command injection vulnerability exists in the TDDPv2 service (\u003ccode\u003e/usr/bin/tddp\u003c/code\u003e) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the \u003ccode\u003esetProductVer\u003c/code\u003e command handler to execute arbitrary operating system commands as root during device boot.\u0026nbsp;\u003c/div\u003e\u003cdiv\u003eSuccessful exploitation may result in complete device compromise through arbitrary command execution with root privileges.\u003c/div\u003e"
}
],
"value": "A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot.\u00a0\n\nSuccessful exploitation may result in complete device compromise through arbitrary command execution with root privileges."
}
],
"impacts": [
{
"capecId": "CAPEC-88",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-88 OS Command Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:48:42.953Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/archer-ax90/v1/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-ax90/v1/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5323/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "TDDPv2 setProductVer Command Injection in Archer AX90",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-84682",
"datePublished": "2026-10-01T18:48:42.953Z",
"dateReserved": "2026-09-01T22:24:51.457Z",
"dateUpdated": "2026-10-02T03:55:36.196Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-9032 (GCVE-0-2026-9032)
Vulnerability from nvd – Published: 2026-10-01 17:41 – Updated: 2026-10-01 17:41
VLAI
EPSS
VEX
Title
Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerability in TP-Link Tapo C120 & C200
Summary
Tapo C120 v1 and C200 v5
contain a NULL pointer dereference in the HTTPS onboarding connect request parser. The interface is reachable without
authentication after initial setup and does not validate that a password field
is present for certain authentication and encryption parameter combinations,
allowing a malformed request from the same local network to crash the HTTPS service
Successful exploitation may
temporarily make HTTPS management functions unavailable. Repeated malformed
requests may sustain the denial-of-service condition, and recovery may in some
cases require a device reboot.
Severity
CWE
- CWE-476 - NULL pointer dereference
Assigner
References
5 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C200 V5 |
Affected:
0 , < V5_1.4.6 Build 260709 Rel.27675n
(custom)
|
|
| TP-Link Systems Inc. | Tapo C120 V1 |
Affected:
0 , < V1_1.9.4 Build 260813 Rel.79754n
(custom)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Tapo C200 V5",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Tapo C120 V1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eTapo C120 v1 and C200 v5\ncontain a NULL pointer dereference in the HTTPS onboarding connect request parser.\u0026nbsp; The interface is reachable without\nauthentication after initial setup and does not validate that a password field\nis present for certain authentication and encryption parameter combinations,\nallowing a malformed request from the same local network to crash the HTTPS service\n\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003e\u003cb\u003e\u0026nbsp;\u003c/b\u003eSuccessful exploitation may\ntemporarily make HTTPS management functions unavailable. Repeated malformed\nrequests may sustain the denial-of-service condition, and recovery may in some\ncases require a device reboot.\u003c/p\u003e"
}
],
"value": "Tapo C120 v1 and C200 v5\ncontain a NULL pointer dereference in the HTTPS onboarding connect request parser.\u00a0 The interface is reachable without\nauthentication after initial setup and does not validate that a password field\nis present for certain authentication and encryption parameter combinations,\nallowing a malformed request from the same local network to crash the HTTPS service\n\n\n\n\n\n\n\n\n\n\n\u00a0Successful exploitation may\ntemporarily make HTTPS management functions unavailable. Repeated malformed\nrequests may sustain the denial-of-service condition, and recovery may in some\ncases require a device reboot."
}
],
"impacts": [
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Overflow Buffers"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-476",
"description": "CWE-476 NULL pointer dereference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:41:31.004Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5321/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerability in TP-Link Tapo C120 \u0026 C200",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-9032",
"datePublished": "2026-10-01T17:41:31.004Z",
"dateReserved": "2026-05-19T16:30:36.090Z",
"dateUpdated": "2026-10-01T17:41:31.004Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-78578 (GCVE-0-2026-78578)
Vulnerability from nvd – Published: 2026-10-01 17:42 – Updated: 2026-10-01 18:08
VLAI
EPSS
VEX
Title
Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Service Vulnerability in TP-Link Tapo C120 & C200
Summary
Tapo C120 v1 and C200 v5
do not enforce authentication for do method HTTPS onboarding connect actions
after initial setup. An unauthenticated adjacent
attacker can submit unauthorized wireless configuration parameters, causing the
camera to attempt connection to a different network.
Successful
exploitation disconnects the camera from its intended wireless network, making
it unreachable on its management address, resulting in a denial-of-service
condition.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:08 UTC
CWE
- CWE-306 - Missing authentication for critical function
Assigner
References
5 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C200 v5 |
Affected:
0 , < V5_1.4.6 Build 260709 Rel.27675n
(custom)
|
|
| TP-Link Systems Inc. | Tapo C120 v1 |
Affected:
0 , < V1_1.9.4 Build 260813 Rel.79754n
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-78578",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:08:21.543786Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:08:30.649Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Tapo C200 v5",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Tapo C120 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eTapo C120 v1 and C200 v5\ndo not enforce authentication for do method HTTPS onboarding connect actions\nafter initial setup.\u0026nbsp; An unauthenticated adjacent\nattacker can submit unauthorized wireless configuration parameters, causing the\ncamera to attempt connection to a different network.\u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation disconnects the camera from its intended wireless network, making\nit unreachable on its management address, resulting in a denial-of-service\ncondition.\u003c/p\u003e"
}
],
"value": "Tapo C120 v1 and C200 v5\ndo not enforce authentication for do method HTTPS onboarding connect actions\nafter initial setup.\u00a0 An unauthenticated adjacent\nattacker can submit unauthorized wireless configuration parameters, causing the\ncamera to attempt connection to a different network.\n\n\n\n\n\nSuccessful\nexploitation disconnects the camera from its intended wireless network, making\nit unreachable on its management address, resulting in a denial-of-service\ncondition."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "CWE-306 Missing authentication for critical function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:42:05.535Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5321/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated do Method Onboarding Connect Allows Wi\u2011Fi Reconfiguration Denial of Service Vulnerability in TP-Link Tapo C120 \u0026 C200",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-78578",
"datePublished": "2026-10-01T17:42:05.535Z",
"dateReserved": "2026-08-24T20:46:19.845Z",
"dateUpdated": "2026-10-01T18:08:30.649Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-78577 (GCVE-0-2026-78577)
Vulnerability from nvd – Published: 2026-10-01 17:41 – Updated: 2026-10-01 18:08
VLAI
EPSS
VEX
Title
Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200
Summary
Tapo C120 v1 and C200 V5
contain a vulnerability in the HTTPS onboarding scan function due to missing authentication.
After initial setup, an unauthenticated attacker on the same local network can
invoke the scan action and retrieve nearby wireless access-point metadata,
including SSIDs, BSSIDs, authentication and encryption modes, and
signal-strength information.
Successful
exploitation may disclose information about the wireless environment
surrounding the camera, allowing an attacker to learn elements of the local
wireless topology.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:08 UTC
CWE
- CWE-306 - Missing authentication for critical function
Assigner
References
5 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C200 v5 |
Affected:
0 , < V5_1.4.6 Build 260709 Rel.27675n
(custom)
|
|
| TP-Link Systems Inc. | Tapo C120 v1 |
Affected:
0 , < V1_1.9.4 Build 260813 Rel.79754n
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-78577",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:08:50.711151Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:08:59.956Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Tapo C200 v5",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Tapo C120 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eTapo C120 v1 and C200 V5\ncontain a vulnerability in the HTTPS onboarding scan function due to missing authentication.\nAfter initial setup, an unauthenticated attacker on the same local network can\ninvoke the scan action and retrieve nearby wireless access-point metadata,\nincluding SSIDs, BSSIDs, authentication and encryption modes, and\nsignal-strength information.\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful\nexploitation may disclose information about the wireless environment\nsurrounding the camera, allowing an attacker to learn elements of the local\nwireless topology.\u0026nbsp;\u003cb\u003e\u003c/b\u003e\u003c/p\u003e"
}
],
"value": "Tapo C120 v1 and C200 V5\ncontain a vulnerability in the HTTPS onboarding scan function due to missing authentication.\nAfter initial setup, an unauthenticated attacker on the same local network can\ninvoke the scan action and retrieve nearby wireless access-point metadata,\nincluding SSIDs, BSSIDs, authentication and encryption modes, and\nsignal-strength information.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may disclose information about the wireless environment\nsurrounding the camera, allowing an attacker to learn elements of the local\nwireless topology."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "CWE-306 Missing authentication for critical function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:41:49.774Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5321/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 \u0026 C200",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-78577",
"datePublished": "2026-10-01T17:41:49.774Z",
"dateReserved": "2026-08-24T20:46:18.534Z",
"dateUpdated": "2026-10-01T18:08:59.956Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102369 (GCVE-0-2026-102369)
Vulnerability from nvd – Published: 2026-10-01 17:42 – Updated: 2026-10-01 18:08
VLAI
EPSS
VEX
Title
Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 & C200
Summary
Tapo C120 v1 and C200 V5
do not adequately protect login challenge data or sanitize
attacker-controlled input processed by the MacTool handler. An unauthenticated
attacker on the same local network can replay login challenge data to obtain an
administrative session, enable a privileged service that becomes accessible
after a reboot, and submit crafted input to execute arbitrary commands within
the device management process.
Successful
exploitation may allow arbitrary command execution on the camera and compromise
the confidentiality, integrity, and availability of the affected device.
Exploitation requires access from the same local network, replay of the login
challenge data, activation of the privileged service, and a device reboot.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:07 UTC
CWE
- CWE-287 - Improper Authentication
Assigner
References
5 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C200 v5 |
Affected:
0 , < V5_1.4.6 Build 260709 Rel.27675n
(custom)
|
|
| TP-Link Systems Inc. | Tapo C120 v1 |
Affected:
0 , < V1_1.9.4 Build 260813 Rel.79754n
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102369",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:07:54.890490Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:08:05.015Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Tapo C200 v5",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Tapo C120 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eTapo C120 v1 and C200 V5\ndo not adequately protect login challenge data or sanitize\nattacker-controlled input processed by the MacTool handler. An unauthenticated\nattacker on the same local network can replay login challenge data to obtain an\nadministrative session, enable a privileged service that becomes accessible\nafter a reboot, and submit crafted input to execute arbitrary commands within\nthe device management process.\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful\nexploitation may allow arbitrary command execution on the camera and compromise\nthe confidentiality, integrity, and availability of the affected device.\nExploitation requires access from the same local network, replay of the login\nchallenge data, activation of the privileged service, and a device reboot.\u003c/p\u003e"
}
],
"value": "Tapo C120 v1 and C200 V5\ndo not adequately protect login challenge data or sanitize\nattacker-controlled input processed by the MacTool handler. An unauthenticated\nattacker on the same local network can replay login challenge data to obtain an\nadministrative session, enable a privileged service that becomes accessible\nafter a reboot, and submit crafted input to execute arbitrary commands within\nthe device management process.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow arbitrary command execution on the camera and compromise\nthe confidentiality, integrity, and availability of the affected device.\nExploitation requires access from the same local network, replay of the login\nchallenge data, activation of the privileged service, and a device reboot."
}
],
"impacts": [
{
"capecId": "CAPEC-21",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-21 Exploitation of Trusted Identifiers"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:42:25.482Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5321/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 \u0026 C200",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-102369",
"datePublished": "2026-10-01T17:42:25.482Z",
"dateReserved": "2026-09-28T23:02:41.717Z",
"dateUpdated": "2026-10-01T18:08:05.015Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84941 (GCVE-0-2026-84941)
Vulnerability from nvd – Published: 2026-09-10 23:35 – Updated: 2026-09-11 13:16
VLAI
EPSS
VEX
Title
Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read
Summary
An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-11 13:10 UTC
CWE
- CWE-611 - Improper restriction of XML external entity reference
Assigner
References
5 references
Impacted products
9 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Omada Software Controller (Windows) |
Affected:
0 , < 6.2.14.11
(custom)
|
|
| TP-Link Systems Inc. | Omada Software Controller (Linux) |
Affected:
0 , < 6.2.14.11
(custom)
|
|
| TP-Link Systems Inc. | OC2000 v1 |
Affected:
0 , < 1.41.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC2000 v2 |
Affected:
0 , < 2.26.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC200 v3 |
Affected:
0 , < 3.3.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC220 v1 |
Affected:
0 , < 1.6.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC220 v2 |
Affected:
0 , < 2.5.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC300 v1 |
Affected:
0 , < 1.35.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC400 v1 |
Affected:
0 , < 1.13.11 Build 20260711
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-84941",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-11T13:10:27.244979Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T13:16:12.359Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "Omada Software Controller (Windows)",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "6.2.14.11",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "Omada Software Controller (Linux)",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "6.2.14.11",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC2000 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.41.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC2000 v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.26.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC200 v3",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "3.3.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC220 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.6.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC220 v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.5.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC300 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.35.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC400 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.13.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "erikdejong"
},
{
"lang": "en",
"type": "finder",
"value": "mattgsys"
},
{
"lang": "en",
"type": "finder",
"value": "eslam moneer (tohtmosiii)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003eAn information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.\u003c/div\u003e"
}
],
"value": "An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information."
}
],
"impacts": [
{
"capecId": "CAPEC-221",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-221 Data Serialization External Entities Blowup"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-611",
"description": "CWE-611 Improper restriction of XML external entity reference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T23:35:53.023Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://support.omadanetworks.com/en/download/software/omada-controller"
},
{
"tags": [
"patch"
],
"url": "https://support.omadanetworks.com/us/download/software/omada-controller"
},
{
"tags": [
"patch"
],
"url": "https://www.omadanetworks.com/en/support/download/"
},
{
"tags": [
"patch"
],
"url": "https://www.omadanetworks.com/us/support/download/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://support.omadanetworks.com/en/document/133722/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-84941",
"datePublished": "2026-09-10T23:35:53.023Z",
"dateReserved": "2026-09-02T16:45:11.015Z",
"dateUpdated": "2026-09-11T13:16:12.359Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-17176 (GCVE-0-2026-17176)
Vulnerability from nvd – Published: 2026-09-10 23:14 – Updated: 2026-10-01 17:55
VLAI
EPSS
VEX
Title
OS Command Injection Vulnerability in Deco Devices
Summary
An OS
command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an
adjacent network attacker to execute arbitrary commands with root privileges by
sending a crafted UDP packet.
Successful exploitation may lead to complete
device compromise, including unauthorized command execution, modification of
device settings, and loss of confidentiality, integrity, and availability
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-11 14:32 UTC
CWE
- CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
Assigner
References
4 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Deco BE11000 V2 |
Affected:
0 , < 1.3.5 Build 26071712
(custom)
|
|
| TP-Link Systems Inc. | Deco M9 Plus V2 |
Affected:
0 , < 1.9.2 Build 20260818
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-17176",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-11T14:32:22.502230Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T14:32:34.104Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"tddp"
],
"product": "Deco BE11000 V2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.3.5 Build 26071712",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"modules": [
"tddp"
],
"product": "Deco M9 Plus V2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.9.2 Build 20260818",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Isa Roovers"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn OS\ncommand injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an\nadjacent network attacker to execute arbitrary commands with root privileges by\nsending a crafted UDP packet.\u003c/p\u003e\n\nSuccessful exploitation may lead to complete\ndevice compromise, including unauthorized command execution, modification of\ndevice settings, and loss of confidentiality, integrity, and availability"
}
],
"value": "An OS\ncommand injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an\nadjacent network attacker to execute arbitrary commands with root privileges by\nsending a crafted UDP packet.\n\n\n\nSuccessful exploitation may lead to complete\ndevice compromise, including unauthorized command execution, modification of\ndevice settings, and loss of confidentiality, integrity, and availability"
}
],
"impacts": [
{
"capecId": "CAPEC-248",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-248 Command Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:55:21.166Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/deco-be11000/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/en/support/faq/5293/"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/deco-m9-plus/v2/"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/deco-m9-plus/v2/#Firmware"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "OS Command Injection Vulnerability in Deco Devices",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-17176",
"datePublished": "2026-09-10T23:14:33.974Z",
"dateReserved": "2026-07-24T18:24:49.819Z",
"dateUpdated": "2026-10-01T17:55:21.166Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76653 (GCVE-0-2026-76653)
Vulnerability from nvd – Published: 2026-09-10 20:12 – Updated: 2026-09-10 20:27
VLAI
EPSS
VEX
Title
Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR600
Summary
A missing
authentication vulnerability in the VPN configuration management has been
identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker
may be able to access and modify VPN configuration information without valid
credentials.
Successful
exploitation may allow a remote unauthenticated attacker to disclose and modify
VPN configuration information.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-10 20:27 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/tl-mr… | patch |
| https://www.tp-link.com/en/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5292/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v8 |
Affected:
0 , < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n
(custom)
|
|
| TP-Link Systems Inc. | Archer MR600 |
Affected:
v3 , < MR600(EU)_V3_1.4.0 Build 260827
(custom)
Affected: v2 , < MR600(EU)_V2_1.12.0 Build 2600826 (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76653",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T20:27:12.333163Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T20:27:18.091Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "TL-MR6400 v8",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "Archer MR600",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "MR600(EU)_V3_1.4.0 Build 260827",
"status": "affected",
"version": "v3",
"versionType": "custom"
},
{
"lessThan": "MR600(EU)_V2_1.12.0 Build 2600826",
"status": "affected",
"version": "v2",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003e\u003cspan\u003eA missing\nauthentication vulnerability in the VPN configuration management has been\nidentified\u0026nbsp;\u003c/span\u003e\u003cspan\u003ein Archer MR600 (v2, v3 \u0026amp; v5) and TL-MR6400 v8\u003c/span\u003e\u003cspan\u003e\u0026nbsp;\u003c/span\u003e\u003cspan\u003edue to improper access control; a remote unauthenticated attacker\nmay be able to access and modify VPN configuration information without valid\ncredentials.\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful\nexploitation may allow a remote unauthenticated attacker to disclose and modify\nVPN configuration information.\u003c/p\u003e"
}
],
"value": "A missing\nauthentication vulnerability in the VPN configuration management has been\nidentified\u00a0in Archer MR600 (v2, v3 \u0026 v5) and TL-MR6400 v8\u00a0due to improper access control; a remote unauthenticated attacker\nmay be able to access and modify VPN configuration information without valid\ncredentials.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow a remote unauthenticated attacker to disclose and modify\nVPN configuration information."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-126",
"description": "CWE-126",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T20:12:43.207Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5292/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR600",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-76653",
"datePublished": "2026-09-10T20:12:43.207Z",
"dateReserved": "2026-08-19T15:49:30.548Z",
"dateUpdated": "2026-09-10T20:27:18.091Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76652 (GCVE-0-2026-76652)
Vulnerability from nvd – Published: 2026-09-10 20:12 – Updated: 2026-09-10 20:27
VLAI
EPSS
VEX
Title
Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600
Summary
An
authenticated directory traversal vulnerability in file upload functionality has
been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file
information, an authenticated remote attacker with access to the affected
upload functionality could upload a specially crafted file and cause it to be
written outside the intended directory.
Successful
exploitation could allow an authenticated remote attacker to write files to
unintended locations, potentially overwriting or modifying files
accessible to the affected service; arbitrary code execution has not
been demonstrated.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-10 20:26 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/tl-mr… | patch |
| https://www.tp-link.com/en/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5292/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v8 |
Affected:
0 , < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n
(custom)
|
|
| TP-Link Systems Inc. | Archer MR600 |
Affected:
v3 , < MR600(EU)_V3_1.4.0 Build 260827
(custom)
Affected: v5 , < MR600(EU)_V5_1.9.0 Build 260805 (custom) Affected: v2 , < MR600(EU)_V2_1.12.0 Build 2600826 (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76652",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T20:26:30.638965Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T20:27:00.302Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "TL-MR6400 v8",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "Archer MR600",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "MR600(EU)_V3_1.4.0 Build 260827",
"status": "affected",
"version": "v3",
"versionType": "custom"
},
{
"lessThan": "MR600(EU)_V5_1.9.0 Build 260805",
"status": "affected",
"version": "v5",
"versionType": "custom"
},
{
"lessThan": "MR600(EU)_V2_1.12.0 Build 2600826",
"status": "affected",
"version": "v2",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn\nauthenticated directory traversal vulnerability in file upload functionality has\nbeen identified in Archer MR600 (v2, v3 \u0026amp; v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file\ninformation, an authenticated remote attacker with access to the affected\nupload functionality could upload a specially crafted file and cause it to be\nwritten outside the intended directory. \u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation could allow an authenticated remote attacker to write files to\nunintended locations, potentially overwriting or\u0026nbsp;modifying\u0026nbsp;files\naccessible to the affected service; arbitrary code execution has not\nbeen\u0026nbsp;demonstrated.\u0026nbsp;\u003c/p\u003e"
}
],
"value": "An\nauthenticated directory traversal vulnerability in file upload functionality has\nbeen identified in Archer MR600 (v2, v3 \u0026 v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file\ninformation, an authenticated remote attacker with access to the affected\nupload functionality could upload a specially crafted file and cause it to be\nwritten outside the intended directory. \n\n\n\n\n\nSuccessful\nexploitation could allow an authenticated remote attacker to write files to\nunintended locations, potentially overwriting or\u00a0modifying\u00a0files\naccessible to the affected service; arbitrary code execution has not\nbeen\u00a0demonstrated."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T20:12:50.706Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5292/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-76652",
"datePublished": "2026-09-10T20:12:50.706Z",
"dateReserved": "2026-08-19T15:49:30.548Z",
"dateUpdated": "2026-09-10T20:27:00.302Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-85384 (GCVE-0-2026-85384)
Vulnerability from nvd – Published: 2026-09-08 18:43 – Updated: 2026-09-10 03:57 Unsupported When Assigned
VLAI
EPSS
VEX
Title
Authenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration Import
Summary
A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.
Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-09 00:00 UTC
CWE
- CWE-121 - Stack-based buffer overflow
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | RE210 AC750 |
Affected:
0 , ≤ 3.14.2 Build 141218 Rel.36430n (EU)
(custom)
Affected: 0 , ≤ 3.14.2 Build 171205 Rel.71984n (US) (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-85384",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-09T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T03:57:38.353Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"/usr/bin/httpd"
],
"product": "RE210 AC750",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThanOrEqual": "3.14.2 Build 141218 Rel.36430n (EU)",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThanOrEqual": "3.14.2 Build 171205 Rel.71984n (US)",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Michael Ace Bengil (Archan6el)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003c/div\u003e\u003cdiv\u003e\u003ci\u003e\u003c/i\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eA stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the \u003c/span\u003e\u003ccode\u003esplitString\u003c/code\u003e\u003cspan\u003e function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003eSuccessful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.\u003c/div\u003e\u003c/div\u003e"
}
],
"value": "A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.\n\n\n\n\n\nSuccessful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability."
}
],
"impacts": [
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Overflow Buffers"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "CWE-121 Stack-based buffer overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T18:43:58.166Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"url": "https://www.tp-link.com/en/support/faq/3562/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"tags": [
"unsupported-when-assigned"
],
"title": "Authenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration Import",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-85384",
"datePublished": "2026-09-08T18:43:58.166Z",
"dateReserved": "2026-09-03T18:02:10.505Z",
"dateUpdated": "2026-09-10T03:57:38.353Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-81531 (GCVE-0-2026-81531)
Vulnerability from nvd – Published: 2026-09-08 16:53 – Updated: 2026-09-21 18:01
VLAI
EPSS
VEX
Title
Unauthenticated Account Information Disclosure in Multiple Omada Controllers
Summary
An information
disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization
remains accessible after completion and may disclose account-related
information to unauthenticated remote users.
Successful
exploitation may allow an attacker to remote query the affected endpoint that
may facilitate user enumeration and subsequent attacks targeting administrative
accounts.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-08 17:21 UTC
CWE
- CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://support.omadanetworks.com/us/download/sof… | patch |
| https://support.omadanetworks.com/us/document/133567/ | vendor-advisory |
| https://support.omadanetworks.com/en/download/sof… | patch |
Impacted products
8 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link System Inc. | Omada Software Controller |
Affected:
0 , < 6.3.0.45
(custom)
|
|
| TP-Link Systems Inc. | OC200 V1 |
Affected:
0 , < (UN)_V1_1.42.10 Build 20260825
(custom)
|
|
| TP Link Systems Inc. | OC200 v2 |
Affected:
0 , < (UN)_V2_2.27.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc | OC200 v3 |
Affected:
0 , < (UN)_V3_3.4.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc. | OC220 v1 |
Affected:
0 , < (UN)_V1_1.7.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc | OC220 v2 |
Affected:
0 , < (UN)_V2_2.6.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc. | OC300 v1 |
Affected:
0 , < (UN)_V1_1.36.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc. | OC400 v1 |
Affected:
0 , < (UN)_V1_1.14.10 Build 20260825
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-81531",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-08T17:21:39.911958Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T17:21:54.913Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Windows",
"Linux"
],
"product": "Omada Software Controller",
"vendor": "TP-Link System Inc.",
"versions": [
{
"lessThan": "6.3.0.45",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC200 V1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V1_1.42.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC200 v2",
"vendor": "TP Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V2_2.27.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC200 v3",
"vendor": "TP-Link Systems Inc",
"versions": [
{
"lessThan": "(UN)_V3_3.4.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC220 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V1_1.7.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC220 v2",
"vendor": "TP-Link Systems Inc",
"versions": [
{
"lessThan": "(UN)_V2_2.6.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC300 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V1_1.36.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC400 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V1_1.14.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Joshua Chan, GitHub: https://github.com/popcorn94, Twitter: popc0rn94"
},
{
"lang": "en",
"type": "finder",
"value": "eslam moneer (tohtmosiii)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn information\ndisclosure vulnerability has been identified in Omada Controller.\u0026nbsp; An API endpoint intended for Controller initialization\nremains accessible after completion and may disclose account-related\ninformation to unauthenticated remote users.\u0026nbsp;\n\u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation may allow an attacker to remote query the affected endpoint that\nmay facilitate user enumeration and subsequent attacks targeting administrative\naccounts.\u003c/p\u003e"
}
],
"value": "An information\ndisclosure vulnerability has been identified in Omada Controller.\u00a0 An API endpoint intended for Controller initialization\nremains accessible after completion and may disclose account-related\ninformation to unauthenticated remote users.\u00a0\n\n\n\n\n\n\nSuccessful\nexploitation may allow an attacker to remote query the affected endpoint that\nmay facilitate user enumeration and subsequent attacks targeting administrative\naccounts."
}
],
"impacts": [
{
"capecId": "CAPEC-118",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-118 Collect \u0026 Analyze Information"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T18:01:46.384Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://support.omadanetworks.com/us/download/software/omada-controller/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://support.omadanetworks.com/us/document/133567/"
},
{
"tags": [
"patch"
],
"url": "https://support.omadanetworks.com/en/download/software/omada-controller/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Account Information Disclosure in Multiple Omada Controllers",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-81531",
"datePublished": "2026-09-08T16:53:18.786Z",
"dateReserved": "2026-08-26T22:31:50.287Z",
"dateUpdated": "2026-09-21T18:01:46.384Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-18330 (GCVE-0-2026-18330)
Vulnerability from nvd – Published: 2026-09-03 22:24 – Updated: 2026-09-04 18:25
VLAI
EPSS
VEX
Title
Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4
Summary
A hard-coded
cryptographic key vulnerability exists in the web module of TP-Link Archer
AX55 v4. A LAN attacker who captures an HTTP login session may use the known
shared RSA private key to decrypt the administrator password; the
weakened AES session key further reduces the effort required to
compromise session confidentiality.
Successful
exploitation may disclose the administrator password captured from an HTTP
login session and compromise session confidentiality.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-04 17:39 UTC
CWE
- CWE-321 - Use of hard-coded cryptographic key
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5279/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Archer AX55 v4 |
Affected:
0 , < 1.2.1 Build 20260527
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-18330",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T17:39:51.418332Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T18:25:58.339Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"web"
],
"product": "Archer AX55 v4",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.1 Build 20260527",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Tianchang Yang and Syed Rafiul Hussain (SyNSec Lab, Penn State University)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA hard-coded\ncryptographic key vulnerability exists in the\u0026nbsp;web module of TP-Link Archer\nAX55 v4. A LAN attacker who captures an HTTP login session may use the known\nshared RSA private key to decrypt the\u0026nbsp;administrator\u0026nbsp;password; the\nweakened AES session key further reduces the effort\u0026nbsp;required\u0026nbsp;to\ncompromise session confidentiality.\u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation may disclose the administrator password captured from an HTTP\nlogin session and compromise session confidentiality.\u0026nbsp;\u003c/p\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e"
}
],
"value": "A hard-coded\ncryptographic key vulnerability exists in the\u00a0web module of TP-Link Archer\nAX55 v4. A LAN attacker who captures an HTTP login session may use the known\nshared RSA private key to decrypt the\u00a0administrator\u00a0password; the\nweakened AES session key further reduces the effort\u00a0required\u00a0to\ncompromise session confidentiality.\n\n\n\n\n\nSuccessful\nexploitation may disclose the administrator password captured from an HTTP\nlogin session and compromise session confidentiality."
}
],
"impacts": [
{
"capecId": "CAPEC-117",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-117 Interception"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-321",
"description": "CWE-321 Use of hard-coded cryptographic key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T22:24:45.430Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/archer-ax55/v4/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5279/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-18330",
"datePublished": "2026-09-03T22:24:45.430Z",
"dateReserved": "2026-07-29T20:03:53.524Z",
"dateUpdated": "2026-09-04T18:25:58.339Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-18167 (GCVE-0-2026-18167)
Vulnerability from nvd – Published: 2026-09-03 22:24 – Updated: 2026-09-04 18:25
VLAI
EPSS
VEX
Title
Stack-based buffer overflow in TP-Link Archer AX55 v4
Summary
A
stack-based buffer overflow vulnerability exists in the EasyMesh module of
TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit
crafted input that causes the easymesh daemon to crash and may potentially
achieve remote code execution on the device.
Successful
exploitation may cause the EasyMesh daemon to crash and may potentially allow
remote code execution when Mesh mode is enabled. This
may result in high impact to the confidentiality, integrity, and availability
of the affected device.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-04 17:09 UTC
CWE
- CWE-121 - Stack-based buffer overflow
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5279/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Archer AX55 v4 |
Affected:
0 , < 1.2.1 Build 20260527
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-18167",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T17:09:09.470755Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T18:25:53.240Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"easymesh"
],
"product": "Archer AX55 v4",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.1 Build 20260527",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Tianchang Yang and Syed Rafiul Hussain (SyNSec Lab, Penn State University)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA\nstack-based buffer overflow vulnerability exists in the EasyMesh module of\nTP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit\ncrafted input that causes the easymesh daemon to crash and may potentially\nachieve remote code execution on the device.\u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation may cause the EasyMesh daemon to crash and may potentially allow\nremote code execution when Mesh mode is enabled. This\nmay result in high impact to the confidentiality, integrity, and availability\nof the affected device.\u003c/p\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e"
}
],
"value": "A\nstack-based buffer overflow vulnerability exists in the EasyMesh module of\nTP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit\ncrafted input that causes the easymesh daemon to crash and may potentially\nachieve remote code execution on the device.\n\n\n\n\n\nSuccessful\nexploitation may cause the EasyMesh daemon to crash and may potentially allow\nremote code execution when Mesh mode is enabled. This\nmay result in high impact to the confidentiality, integrity, and availability\nof the affected device."
}
],
"impacts": [
{
"capecId": "CAPEC-47",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-47 Buffer Overflow via Parameter Expansion"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "CWE-121 Stack-based buffer overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T22:24:57.369Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/archer-ax55/v4/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5279/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Stack-based buffer overflow in TP-Link Archer AX55 v4",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-18167",
"datePublished": "2026-09-03T22:24:57.369Z",
"dateReserved": "2026-07-28T20:48:04.039Z",
"dateUpdated": "2026-09-04T18:25:53.240Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102370 (GCVE-0-2026-102370)
Vulnerability from cvelistv5 – Published: 2026-10-01 20:47 – Updated: 2026-10-01 21:01
VLAI
EPSS
VEX
Title
Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71
Summary
Kasa EC70 v4
and EC71 v4 do not logically disable the production debug interface at the
firmware or chip level and do not lock the bootloader. Although the debug traces are physically
severed during manufacturing, an attacker with physical access can restore the
connection, interrupt the boot process, and manipulate boot parameters to enter
a non-standard initialization path that exposes an unauthenticated root shell
during startup.
Successful exploitation may allow an
attacker with physical access to obtain root-level command access during device
startup, resulting in loss of confidentiality, integrity, and availability for
the affected device. Exploitation requires device disassembly, restoration of
the severed debug connection, and manipulation of the boot process.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 21:01 UTC
CWE
- CWE-1191 - On-Chip debug and test interface with improper access control
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/ec71/… | patch |
| https://www.tp-link.com/us/support/download/ec70/… | patch |
| https://www.tp-link.com/us/support/faq/5324/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Kasa EC70 V4 |
Affected:
0 , < 2.4.3 Build 20260902 rel.4511
(custom)
|
|
| TP-Link Systems Inc. | Kasa EC71 V4 |
Affected:
0 , < 2.4.3 Build 20260902 rel.4511
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102370",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T21:01:19.841347Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T21:01:44.613Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Kasa EC70 V4",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.4.3 Build 20260902 rel.4511",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Kasa EC71 V4",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.4.3 Build 20260902 rel.4511",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Christopher Childress"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eKasa EC70 v4\nand EC71 v4 do not logically disable the production debug interface at the\nfirmware or chip level and do not lock the bootloader.\u0026nbsp; Although the debug traces are physically\nsevered during manufacturing, an attacker with physical access can restore the\nconnection, interrupt the boot process, and manipulate boot parameters to enter\na non-standard initialization path that exposes an unauthenticated root shell\nduring startup.\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful exploitation may allow an\nattacker with physical access to obtain root-level command access during device\nstartup, resulting in loss of confidentiality, integrity, and availability for\nthe affected device. Exploitation requires device disassembly, restoration of\nthe severed debug connection, and manipulation of the boot process.\u003cb\u003e \u003c/b\u003e\u003c/p\u003e"
}
],
"value": "Kasa EC70 v4\nand EC71 v4 do not logically disable the production debug interface at the\nfirmware or chip level and do not lock the bootloader.\u00a0 Although the debug traces are physically\nsevered during manufacturing, an attacker with physical access can restore the\nconnection, interrupt the boot process, and manipulate boot parameters to enter\na non-standard initialization path that exposes an unauthenticated root shell\nduring startup.\n\n\n\n\n\n\n\n\n\nSuccessful exploitation may allow an\nattacker with physical access to obtain root-level command access during device\nstartup, resulting in loss of confidentiality, integrity, and availability for\nthe affected device. Exploitation requires device disassembly, restoration of\nthe severed debug connection, and manipulation of the boot process."
}
],
"impacts": [
{
"capecId": "CAPEC-116",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-116 Excavation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "PHYSICAL",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1191",
"description": "CWE-1191 On-Chip debug and test interface with improper access control",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T20:47:30.211Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/ec71/v4/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5324/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-102370",
"datePublished": "2026-10-01T20:47:30.211Z",
"dateReserved": "2026-09-28T23:32:02.361Z",
"dateUpdated": "2026-10-01T21:01:44.613Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84682 (GCVE-0-2026-84682)
Vulnerability from cvelistv5 – Published: 2026-10-01 18:48 – Updated: 2026-10-02 03:55
VLAI
EPSS
VEX
Title
TDDPv2 setProductVer Command Injection in Archer AX90
Summary
A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot.
Successful exploitation may result in complete device compromise through arbitrary command execution with root privileges.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 00:00 UTC
CWE
- CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/arche… | patch |
| https://www.tp-link.com/en/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5323/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Archer AX90 v1 |
Affected:
0 , < 1.1.4 Build 20260927
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-84682",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T03:55:36.196Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"tddp"
],
"product": "Archer AX90 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.1.4 Build 20260927",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Can Oztas"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003eA command injection vulnerability exists in the TDDPv2 service (\u003ccode\u003e/usr/bin/tddp\u003c/code\u003e) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the \u003ccode\u003esetProductVer\u003c/code\u003e command handler to execute arbitrary operating system commands as root during device boot.\u0026nbsp;\u003c/div\u003e\u003cdiv\u003eSuccessful exploitation may result in complete device compromise through arbitrary command execution with root privileges.\u003c/div\u003e"
}
],
"value": "A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot.\u00a0\n\nSuccessful exploitation may result in complete device compromise through arbitrary command execution with root privileges."
}
],
"impacts": [
{
"capecId": "CAPEC-88",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-88 OS Command Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:48:42.953Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/archer-ax90/v1/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-ax90/v1/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5323/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "TDDPv2 setProductVer Command Injection in Archer AX90",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-84682",
"datePublished": "2026-10-01T18:48:42.953Z",
"dateReserved": "2026-09-01T22:24:51.457Z",
"dateUpdated": "2026-10-02T03:55:36.196Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-8618 (GCVE-0-2026-8618)
Vulnerability from cvelistv5 – Published: 2026-10-01 18:16 – Updated: 2026-10-01 18:36
VLAI
EPSS
VEX
Title
Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x91 on Deco M9 Plus
Summary
A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:35 UTC
CWE
- CWE-121 - Stack-based buffer overflow
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/deco-… | patch |
| https://www.tp-link.com/us/support/download/deco-… | patch |
| https://www.tp-link.com/us/support/faq/5322/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Deco M9 Plus V2 |
Affected:
0 , < 1.9.2 Build 20260818
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-8618",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:35:59.010450Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:36:18.919Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"tddp"
],
"product": "Deco M9 Plus V2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.9.2 Build 20260818",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Isa Roovers"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003eA stack-based buffer overflow vulnerability exists in the TDDPv2 service (\u003ccode\u003e/usr/bin/tddp\u003c/code\u003e) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype \u003ccode\u003e0x91\u003c/code\u003e handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets.\u003c/div\u003e"
}
],
"value": "A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets."
}
],
"impacts": [
{
"capecId": "CAPEC-123",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-123 Buffer Manipulation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "CWE-121 Stack-based buffer overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:16:32.107Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/deco-m9-plus/v2/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/deco-m9-plus/v2/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5322/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x91 on Deco M9 Plus",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-8618",
"datePublished": "2026-10-01T18:16:32.107Z",
"dateReserved": "2026-05-14T18:04:17.050Z",
"dateUpdated": "2026-10-01T18:36:18.919Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102369 (GCVE-0-2026-102369)
Vulnerability from cvelistv5 – Published: 2026-10-01 17:42 – Updated: 2026-10-01 18:08
VLAI
EPSS
VEX
Title
Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 & C200
Summary
Tapo C120 v1 and C200 V5
do not adequately protect login challenge data or sanitize
attacker-controlled input processed by the MacTool handler. An unauthenticated
attacker on the same local network can replay login challenge data to obtain an
administrative session, enable a privileged service that becomes accessible
after a reboot, and submit crafted input to execute arbitrary commands within
the device management process.
Successful
exploitation may allow arbitrary command execution on the camera and compromise
the confidentiality, integrity, and availability of the affected device.
Exploitation requires access from the same local network, replay of the login
challenge data, activation of the privileged service, and a device reboot.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:07 UTC
CWE
- CWE-287 - Improper Authentication
Assigner
References
5 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C200 v5 |
Affected:
0 , < V5_1.4.6 Build 260709 Rel.27675n
(custom)
|
|
| TP-Link Systems Inc. | Tapo C120 v1 |
Affected:
0 , < V1_1.9.4 Build 260813 Rel.79754n
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102369",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:07:54.890490Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:08:05.015Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Tapo C200 v5",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Tapo C120 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eTapo C120 v1 and C200 V5\ndo not adequately protect login challenge data or sanitize\nattacker-controlled input processed by the MacTool handler. An unauthenticated\nattacker on the same local network can replay login challenge data to obtain an\nadministrative session, enable a privileged service that becomes accessible\nafter a reboot, and submit crafted input to execute arbitrary commands within\nthe device management process.\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful\nexploitation may allow arbitrary command execution on the camera and compromise\nthe confidentiality, integrity, and availability of the affected device.\nExploitation requires access from the same local network, replay of the login\nchallenge data, activation of the privileged service, and a device reboot.\u003c/p\u003e"
}
],
"value": "Tapo C120 v1 and C200 V5\ndo not adequately protect login challenge data or sanitize\nattacker-controlled input processed by the MacTool handler. An unauthenticated\nattacker on the same local network can replay login challenge data to obtain an\nadministrative session, enable a privileged service that becomes accessible\nafter a reboot, and submit crafted input to execute arbitrary commands within\nthe device management process.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow arbitrary command execution on the camera and compromise\nthe confidentiality, integrity, and availability of the affected device.\nExploitation requires access from the same local network, replay of the login\nchallenge data, activation of the privileged service, and a device reboot."
}
],
"impacts": [
{
"capecId": "CAPEC-21",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-21 Exploitation of Trusted Identifiers"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:42:25.482Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5321/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 \u0026 C200",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-102369",
"datePublished": "2026-10-01T17:42:25.482Z",
"dateReserved": "2026-09-28T23:02:41.717Z",
"dateUpdated": "2026-10-01T18:08:05.015Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-78578 (GCVE-0-2026-78578)
Vulnerability from cvelistv5 – Published: 2026-10-01 17:42 – Updated: 2026-10-01 18:08
VLAI
EPSS
VEX
Title
Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Service Vulnerability in TP-Link Tapo C120 & C200
Summary
Tapo C120 v1 and C200 v5
do not enforce authentication for do method HTTPS onboarding connect actions
after initial setup. An unauthenticated adjacent
attacker can submit unauthorized wireless configuration parameters, causing the
camera to attempt connection to a different network.
Successful
exploitation disconnects the camera from its intended wireless network, making
it unreachable on its management address, resulting in a denial-of-service
condition.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:08 UTC
CWE
- CWE-306 - Missing authentication for critical function
Assigner
References
5 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C200 v5 |
Affected:
0 , < V5_1.4.6 Build 260709 Rel.27675n
(custom)
|
|
| TP-Link Systems Inc. | Tapo C120 v1 |
Affected:
0 , < V1_1.9.4 Build 260813 Rel.79754n
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-78578",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:08:21.543786Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:08:30.649Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Tapo C200 v5",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Tapo C120 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eTapo C120 v1 and C200 v5\ndo not enforce authentication for do method HTTPS onboarding connect actions\nafter initial setup.\u0026nbsp; An unauthenticated adjacent\nattacker can submit unauthorized wireless configuration parameters, causing the\ncamera to attempt connection to a different network.\u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation disconnects the camera from its intended wireless network, making\nit unreachable on its management address, resulting in a denial-of-service\ncondition.\u003c/p\u003e"
}
],
"value": "Tapo C120 v1 and C200 v5\ndo not enforce authentication for do method HTTPS onboarding connect actions\nafter initial setup.\u00a0 An unauthenticated adjacent\nattacker can submit unauthorized wireless configuration parameters, causing the\ncamera to attempt connection to a different network.\n\n\n\n\n\nSuccessful\nexploitation disconnects the camera from its intended wireless network, making\nit unreachable on its management address, resulting in a denial-of-service\ncondition."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "CWE-306 Missing authentication for critical function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:42:05.535Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5321/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated do Method Onboarding Connect Allows Wi\u2011Fi Reconfiguration Denial of Service Vulnerability in TP-Link Tapo C120 \u0026 C200",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-78578",
"datePublished": "2026-10-01T17:42:05.535Z",
"dateReserved": "2026-08-24T20:46:19.845Z",
"dateUpdated": "2026-10-01T18:08:30.649Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-78577 (GCVE-0-2026-78577)
Vulnerability from cvelistv5 – Published: 2026-10-01 17:41 – Updated: 2026-10-01 18:08
VLAI
EPSS
VEX
Title
Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200
Summary
Tapo C120 v1 and C200 V5
contain a vulnerability in the HTTPS onboarding scan function due to missing authentication.
After initial setup, an unauthenticated attacker on the same local network can
invoke the scan action and retrieve nearby wireless access-point metadata,
including SSIDs, BSSIDs, authentication and encryption modes, and
signal-strength information.
Successful
exploitation may disclose information about the wireless environment
surrounding the camera, allowing an attacker to learn elements of the local
wireless topology.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:08 UTC
CWE
- CWE-306 - Missing authentication for critical function
Assigner
References
5 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C200 v5 |
Affected:
0 , < V5_1.4.6 Build 260709 Rel.27675n
(custom)
|
|
| TP-Link Systems Inc. | Tapo C120 v1 |
Affected:
0 , < V1_1.9.4 Build 260813 Rel.79754n
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-78577",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:08:50.711151Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:08:59.956Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Tapo C200 v5",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Tapo C120 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eTapo C120 v1 and C200 V5\ncontain a vulnerability in the HTTPS onboarding scan function due to missing authentication.\nAfter initial setup, an unauthenticated attacker on the same local network can\ninvoke the scan action and retrieve nearby wireless access-point metadata,\nincluding SSIDs, BSSIDs, authentication and encryption modes, and\nsignal-strength information.\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful\nexploitation may disclose information about the wireless environment\nsurrounding the camera, allowing an attacker to learn elements of the local\nwireless topology.\u0026nbsp;\u003cb\u003e\u003c/b\u003e\u003c/p\u003e"
}
],
"value": "Tapo C120 v1 and C200 V5\ncontain a vulnerability in the HTTPS onboarding scan function due to missing authentication.\nAfter initial setup, an unauthenticated attacker on the same local network can\ninvoke the scan action and retrieve nearby wireless access-point metadata,\nincluding SSIDs, BSSIDs, authentication and encryption modes, and\nsignal-strength information.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may disclose information about the wireless environment\nsurrounding the camera, allowing an attacker to learn elements of the local\nwireless topology."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "CWE-306 Missing authentication for critical function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:41:49.774Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5321/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 \u0026 C200",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-78577",
"datePublished": "2026-10-01T17:41:49.774Z",
"dateReserved": "2026-08-24T20:46:18.534Z",
"dateUpdated": "2026-10-01T18:08:59.956Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-9032 (GCVE-0-2026-9032)
Vulnerability from cvelistv5 – Published: 2026-10-01 17:41 – Updated: 2026-10-01 17:41
VLAI
EPSS
VEX
Title
Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerability in TP-Link Tapo C120 & C200
Summary
Tapo C120 v1 and C200 v5
contain a NULL pointer dereference in the HTTPS onboarding connect request parser. The interface is reachable without
authentication after initial setup and does not validate that a password field
is present for certain authentication and encryption parameter combinations,
allowing a malformed request from the same local network to crash the HTTPS service
Successful exploitation may
temporarily make HTTPS management functions unavailable. Repeated malformed
requests may sustain the denial-of-service condition, and recovery may in some
cases require a device reboot.
Severity
CWE
- CWE-476 - NULL pointer dereference
Assigner
References
5 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C200 V5 |
Affected:
0 , < V5_1.4.6 Build 260709 Rel.27675n
(custom)
|
|
| TP-Link Systems Inc. | Tapo C120 V1 |
Affected:
0 , < V1_1.9.4 Build 260813 Rel.79754n
(custom)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Tapo C200 V5",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Tapo C120 V1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eTapo C120 v1 and C200 v5\ncontain a NULL pointer dereference in the HTTPS onboarding connect request parser.\u0026nbsp; The interface is reachable without\nauthentication after initial setup and does not validate that a password field\nis present for certain authentication and encryption parameter combinations,\nallowing a malformed request from the same local network to crash the HTTPS service\n\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003e\u003cb\u003e\u0026nbsp;\u003c/b\u003eSuccessful exploitation may\ntemporarily make HTTPS management functions unavailable. Repeated malformed\nrequests may sustain the denial-of-service condition, and recovery may in some\ncases require a device reboot.\u003c/p\u003e"
}
],
"value": "Tapo C120 v1 and C200 v5\ncontain a NULL pointer dereference in the HTTPS onboarding connect request parser.\u00a0 The interface is reachable without\nauthentication after initial setup and does not validate that a password field\nis present for certain authentication and encryption parameter combinations,\nallowing a malformed request from the same local network to crash the HTTPS service\n\n\n\n\n\n\n\n\n\n\n\u00a0Successful exploitation may\ntemporarily make HTTPS management functions unavailable. Repeated malformed\nrequests may sustain the denial-of-service condition, and recovery may in some\ncases require a device reboot."
}
],
"impacts": [
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Overflow Buffers"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-476",
"description": "CWE-476 NULL pointer dereference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:41:31.004Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5321/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerability in TP-Link Tapo C120 \u0026 C200",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-9032",
"datePublished": "2026-10-01T17:41:31.004Z",
"dateReserved": "2026-05-19T16:30:36.090Z",
"dateUpdated": "2026-10-01T17:41:31.004Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84941 (GCVE-0-2026-84941)
Vulnerability from cvelistv5 – Published: 2026-09-10 23:35 – Updated: 2026-09-11 13:16
VLAI
EPSS
VEX
Title
Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read
Summary
An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-11 13:10 UTC
CWE
- CWE-611 - Improper restriction of XML external entity reference
Assigner
References
5 references
Impacted products
9 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Omada Software Controller (Windows) |
Affected:
0 , < 6.2.14.11
(custom)
|
|
| TP-Link Systems Inc. | Omada Software Controller (Linux) |
Affected:
0 , < 6.2.14.11
(custom)
|
|
| TP-Link Systems Inc. | OC2000 v1 |
Affected:
0 , < 1.41.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC2000 v2 |
Affected:
0 , < 2.26.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC200 v3 |
Affected:
0 , < 3.3.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC220 v1 |
Affected:
0 , < 1.6.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC220 v2 |
Affected:
0 , < 2.5.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC300 v1 |
Affected:
0 , < 1.35.11 Build 20260711
(custom)
|
|
| TP-Link Systems Inc. | OC400 v1 |
Affected:
0 , < 1.13.11 Build 20260711
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-84941",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-11T13:10:27.244979Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T13:16:12.359Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "Omada Software Controller (Windows)",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "6.2.14.11",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "Omada Software Controller (Linux)",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "6.2.14.11",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC2000 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.41.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC2000 v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.26.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC200 v3",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "3.3.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC220 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.6.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC220 v2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "2.5.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC300 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.35.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Omada Controller"
],
"product": "OC400 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.13.11 Build 20260711",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "erikdejong"
},
{
"lang": "en",
"type": "finder",
"value": "mattgsys"
},
{
"lang": "en",
"type": "finder",
"value": "eslam moneer (tohtmosiii)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003eAn information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information.\u003c/div\u003e"
}
],
"value": "An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized disclosure of sensitive information."
}
],
"impacts": [
{
"capecId": "CAPEC-221",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-221 Data Serialization External Entities Blowup"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-611",
"description": "CWE-611 Improper restriction of XML external entity reference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T23:35:53.023Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://support.omadanetworks.com/en/download/software/omada-controller"
},
{
"tags": [
"patch"
],
"url": "https://support.omadanetworks.com/us/download/software/omada-controller"
},
{
"tags": [
"patch"
],
"url": "https://www.omadanetworks.com/en/support/download/"
},
{
"tags": [
"patch"
],
"url": "https://www.omadanetworks.com/us/support/download/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://support.omadanetworks.com/en/document/133722/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-84941",
"datePublished": "2026-09-10T23:35:53.023Z",
"dateReserved": "2026-09-02T16:45:11.015Z",
"dateUpdated": "2026-09-11T13:16:12.359Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-17176 (GCVE-0-2026-17176)
Vulnerability from cvelistv5 – Published: 2026-09-10 23:14 – Updated: 2026-10-01 17:55
VLAI
EPSS
VEX
Title
OS Command Injection Vulnerability in Deco Devices
Summary
An OS
command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an
adjacent network attacker to execute arbitrary commands with root privileges by
sending a crafted UDP packet.
Successful exploitation may lead to complete
device compromise, including unauthorized command execution, modification of
device settings, and loss of confidentiality, integrity, and availability
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-11 14:32 UTC
CWE
- CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
Assigner
References
4 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Deco BE11000 V2 |
Affected:
0 , < 1.3.5 Build 26071712
(custom)
|
|
| TP-Link Systems Inc. | Deco M9 Plus V2 |
Affected:
0 , < 1.9.2 Build 20260818
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-17176",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-11T14:32:22.502230Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T14:32:34.104Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"tddp"
],
"product": "Deco BE11000 V2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.3.5 Build 26071712",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"modules": [
"tddp"
],
"product": "Deco M9 Plus V2",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.9.2 Build 20260818",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Isa Roovers"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn OS\ncommand injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an\nadjacent network attacker to execute arbitrary commands with root privileges by\nsending a crafted UDP packet.\u003c/p\u003e\n\nSuccessful exploitation may lead to complete\ndevice compromise, including unauthorized command execution, modification of\ndevice settings, and loss of confidentiality, integrity, and availability"
}
],
"value": "An OS\ncommand injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an\nadjacent network attacker to execute arbitrary commands with root privileges by\nsending a crafted UDP packet.\n\n\n\nSuccessful exploitation may lead to complete\ndevice compromise, including unauthorized command execution, modification of\ndevice settings, and loss of confidentiality, integrity, and availability"
}
],
"impacts": [
{
"capecId": "CAPEC-248",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-248 Command Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T17:55:21.166Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/deco-be11000/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/en/support/faq/5293/"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/deco-m9-plus/v2/"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/deco-m9-plus/v2/#Firmware"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "OS Command Injection Vulnerability in Deco Devices",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-17176",
"datePublished": "2026-09-10T23:14:33.974Z",
"dateReserved": "2026-07-24T18:24:49.819Z",
"dateUpdated": "2026-10-01T17:55:21.166Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76652 (GCVE-0-2026-76652)
Vulnerability from cvelistv5 – Published: 2026-09-10 20:12 – Updated: 2026-09-10 20:27
VLAI
EPSS
VEX
Title
Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600
Summary
An
authenticated directory traversal vulnerability in file upload functionality has
been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file
information, an authenticated remote attacker with access to the affected
upload functionality could upload a specially crafted file and cause it to be
written outside the intended directory.
Successful
exploitation could allow an authenticated remote attacker to write files to
unintended locations, potentially overwriting or modifying files
accessible to the affected service; arbitrary code execution has not
been demonstrated.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-10 20:26 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/tl-mr… | patch |
| https://www.tp-link.com/en/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5292/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v8 |
Affected:
0 , < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n
(custom)
|
|
| TP-Link Systems Inc. | Archer MR600 |
Affected:
v3 , < MR600(EU)_V3_1.4.0 Build 260827
(custom)
Affected: v5 , < MR600(EU)_V5_1.9.0 Build 260805 (custom) Affected: v2 , < MR600(EU)_V2_1.12.0 Build 2600826 (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76652",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T20:26:30.638965Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T20:27:00.302Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "TL-MR6400 v8",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "Archer MR600",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "MR600(EU)_V3_1.4.0 Build 260827",
"status": "affected",
"version": "v3",
"versionType": "custom"
},
{
"lessThan": "MR600(EU)_V5_1.9.0 Build 260805",
"status": "affected",
"version": "v5",
"versionType": "custom"
},
{
"lessThan": "MR600(EU)_V2_1.12.0 Build 2600826",
"status": "affected",
"version": "v2",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn\nauthenticated directory traversal vulnerability in file upload functionality has\nbeen identified in Archer MR600 (v2, v3 \u0026amp; v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file\ninformation, an authenticated remote attacker with access to the affected\nupload functionality could upload a specially crafted file and cause it to be\nwritten outside the intended directory. \u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation could allow an authenticated remote attacker to write files to\nunintended locations, potentially overwriting or\u0026nbsp;modifying\u0026nbsp;files\naccessible to the affected service; arbitrary code execution has not\nbeen\u0026nbsp;demonstrated.\u0026nbsp;\u003c/p\u003e"
}
],
"value": "An\nauthenticated directory traversal vulnerability in file upload functionality has\nbeen identified in Archer MR600 (v2, v3 \u0026 v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file\ninformation, an authenticated remote attacker with access to the affected\nupload functionality could upload a specially crafted file and cause it to be\nwritten outside the intended directory. \n\n\n\n\n\nSuccessful\nexploitation could allow an authenticated remote attacker to write files to\nunintended locations, potentially overwriting or\u00a0modifying\u00a0files\naccessible to the affected service; arbitrary code execution has not\nbeen\u00a0demonstrated."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T20:12:50.706Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5292/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-76652",
"datePublished": "2026-09-10T20:12:50.706Z",
"dateReserved": "2026-08-19T15:49:30.548Z",
"dateUpdated": "2026-09-10T20:27:00.302Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76653 (GCVE-0-2026-76653)
Vulnerability from cvelistv5 – Published: 2026-09-10 20:12 – Updated: 2026-09-10 20:27
VLAI
EPSS
VEX
Title
Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR600
Summary
A missing
authentication vulnerability in the VPN configuration management has been
identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker
may be able to access and modify VPN configuration information without valid
credentials.
Successful
exploitation may allow a remote unauthenticated attacker to disclose and modify
VPN configuration information.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-10 20:27 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/tl-mr… | patch |
| https://www.tp-link.com/en/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5292/ | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v8 |
Affected:
0 , < 1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n
(custom)
|
|
| TP-Link Systems Inc. | Archer MR600 |
Affected:
v3 , < MR600(EU)_V3_1.4.0 Build 260827
(custom)
Affected: v2 , < MR600(EU)_V2_1.12.0 Build 2600826 (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76653",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T20:27:12.333163Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T20:27:18.091Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "TL-MR6400 v8",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.5.0 0.9.1 v0001.0 Build 260610 Rel.67978n",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "Archer MR600",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "MR600(EU)_V3_1.4.0 Build 260827",
"status": "affected",
"version": "v3",
"versionType": "custom"
},
{
"lessThan": "MR600(EU)_V2_1.12.0 Build 2600826",
"status": "affected",
"version": "v2",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003e\u003cspan\u003eA missing\nauthentication vulnerability in the VPN configuration management has been\nidentified\u0026nbsp;\u003c/span\u003e\u003cspan\u003ein Archer MR600 (v2, v3 \u0026amp; v5) and TL-MR6400 v8\u003c/span\u003e\u003cspan\u003e\u0026nbsp;\u003c/span\u003e\u003cspan\u003edue to improper access control; a remote unauthenticated attacker\nmay be able to access and modify VPN configuration information without valid\ncredentials.\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful\nexploitation may allow a remote unauthenticated attacker to disclose and modify\nVPN configuration information.\u003c/p\u003e"
}
],
"value": "A missing\nauthentication vulnerability in the VPN configuration management has been\nidentified\u00a0in Archer MR600 (v2, v3 \u0026 v5) and TL-MR6400 v8\u00a0due to improper access control; a remote unauthenticated attacker\nmay be able to access and modify VPN configuration information without valid\ncredentials.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow a remote unauthenticated attacker to disclose and modify\nVPN configuration information."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-126",
"description": "CWE-126",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T20:12:43.207Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware"
},
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5292/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR600",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-76653",
"datePublished": "2026-09-10T20:12:43.207Z",
"dateReserved": "2026-08-19T15:49:30.548Z",
"dateUpdated": "2026-09-10T20:27:18.091Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-85384 (GCVE-0-2026-85384)
Vulnerability from cvelistv5 – Published: 2026-09-08 18:43 – Updated: 2026-09-10 03:57 Unsupported When Assigned
VLAI
EPSS
VEX
Title
Authenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration Import
Summary
A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.
Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-09 00:00 UTC
CWE
- CWE-121 - Stack-based buffer overflow
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | RE210 AC750 |
Affected:
0 , ≤ 3.14.2 Build 141218 Rel.36430n (EU)
(custom)
Affected: 0 , ≤ 3.14.2 Build 171205 Rel.71984n (US) (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-85384",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-09T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T03:57:38.353Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"/usr/bin/httpd"
],
"product": "RE210 AC750",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThanOrEqual": "3.14.2 Build 141218 Rel.36430n (EU)",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThanOrEqual": "3.14.2 Build 171205 Rel.71984n (US)",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Michael Ace Bengil (Archan6el)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003c/div\u003e\u003cdiv\u003e\u003ci\u003e\u003c/i\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eA stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the \u003c/span\u003e\u003ccode\u003esplitString\u003c/code\u003e\u003cspan\u003e function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003eSuccessful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.\u003c/div\u003e\u003c/div\u003e"
}
],
"value": "A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.\n\n\n\n\n\nSuccessful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability."
}
],
"impacts": [
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Overflow Buffers"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "CWE-121 Stack-based buffer overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T18:43:58.166Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"url": "https://www.tp-link.com/en/support/faq/3562/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"tags": [
"unsupported-when-assigned"
],
"title": "Authenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration Import",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-85384",
"datePublished": "2026-09-08T18:43:58.166Z",
"dateReserved": "2026-09-03T18:02:10.505Z",
"dateUpdated": "2026-09-10T03:57:38.353Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-81531 (GCVE-0-2026-81531)
Vulnerability from cvelistv5 – Published: 2026-09-08 16:53 – Updated: 2026-09-21 18:01
VLAI
EPSS
VEX
Title
Unauthenticated Account Information Disclosure in Multiple Omada Controllers
Summary
An information
disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization
remains accessible after completion and may disclose account-related
information to unauthenticated remote users.
Successful
exploitation may allow an attacker to remote query the affected endpoint that
may facilitate user enumeration and subsequent attacks targeting administrative
accounts.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-08 17:21 UTC
CWE
- CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://support.omadanetworks.com/us/download/sof… | patch |
| https://support.omadanetworks.com/us/document/133567/ | vendor-advisory |
| https://support.omadanetworks.com/en/download/sof… | patch |
Impacted products
8 products
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link System Inc. | Omada Software Controller |
Affected:
0 , < 6.3.0.45
(custom)
|
|
| TP-Link Systems Inc. | OC200 V1 |
Affected:
0 , < (UN)_V1_1.42.10 Build 20260825
(custom)
|
|
| TP Link Systems Inc. | OC200 v2 |
Affected:
0 , < (UN)_V2_2.27.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc | OC200 v3 |
Affected:
0 , < (UN)_V3_3.4.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc. | OC220 v1 |
Affected:
0 , < (UN)_V1_1.7.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc | OC220 v2 |
Affected:
0 , < (UN)_V2_2.6.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc. | OC300 v1 |
Affected:
0 , < (UN)_V1_1.36.10 Build 20260825
(custom)
|
|
| TP-Link Systems Inc. | OC400 v1 |
Affected:
0 , < (UN)_V1_1.14.10 Build 20260825
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-81531",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-08T17:21:39.911958Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T17:21:54.913Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Windows",
"Linux"
],
"product": "Omada Software Controller",
"vendor": "TP-Link System Inc.",
"versions": [
{
"lessThan": "6.3.0.45",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC200 V1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V1_1.42.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC200 v2",
"vendor": "TP Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V2_2.27.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC200 v3",
"vendor": "TP-Link Systems Inc",
"versions": [
{
"lessThan": "(UN)_V3_3.4.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC220 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V1_1.7.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC220 v2",
"vendor": "TP-Link Systems Inc",
"versions": [
{
"lessThan": "(UN)_V2_2.6.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC300 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V1_1.36.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "OC400 v1",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "(UN)_V1_1.14.10 Build 20260825",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Joshua Chan, GitHub: https://github.com/popcorn94, Twitter: popc0rn94"
},
{
"lang": "en",
"type": "finder",
"value": "eslam moneer (tohtmosiii)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn information\ndisclosure vulnerability has been identified in Omada Controller.\u0026nbsp; An API endpoint intended for Controller initialization\nremains accessible after completion and may disclose account-related\ninformation to unauthenticated remote users.\u0026nbsp;\n\u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation may allow an attacker to remote query the affected endpoint that\nmay facilitate user enumeration and subsequent attacks targeting administrative\naccounts.\u003c/p\u003e"
}
],
"value": "An information\ndisclosure vulnerability has been identified in Omada Controller.\u00a0 An API endpoint intended for Controller initialization\nremains accessible after completion and may disclose account-related\ninformation to unauthenticated remote users.\u00a0\n\n\n\n\n\n\nSuccessful\nexploitation may allow an attacker to remote query the affected endpoint that\nmay facilitate user enumeration and subsequent attacks targeting administrative\naccounts."
}
],
"impacts": [
{
"capecId": "CAPEC-118",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-118 Collect \u0026 Analyze Information"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T18:01:46.384Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://support.omadanetworks.com/us/download/software/omada-controller/"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://support.omadanetworks.com/us/document/133567/"
},
{
"tags": [
"patch"
],
"url": "https://support.omadanetworks.com/en/download/software/omada-controller/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Account Information Disclosure in Multiple Omada Controllers",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-81531",
"datePublished": "2026-09-08T16:53:18.786Z",
"dateReserved": "2026-08-26T22:31:50.287Z",
"dateUpdated": "2026-09-21T18:01:46.384Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-18167 (GCVE-0-2026-18167)
Vulnerability from cvelistv5 – Published: 2026-09-03 22:24 – Updated: 2026-09-04 18:25
VLAI
EPSS
VEX
Title
Stack-based buffer overflow in TP-Link Archer AX55 v4
Summary
A
stack-based buffer overflow vulnerability exists in the EasyMesh module of
TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit
crafted input that causes the easymesh daemon to crash and may potentially
achieve remote code execution on the device.
Successful
exploitation may cause the EasyMesh daemon to crash and may potentially allow
remote code execution when Mesh mode is enabled. This
may result in high impact to the confidentiality, integrity, and availability
of the affected device.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-04 17:09 UTC
CWE
- CWE-121 - Stack-based buffer overflow
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5279/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Archer AX55 v4 |
Affected:
0 , < 1.2.1 Build 20260527
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-18167",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T17:09:09.470755Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T18:25:53.240Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"easymesh"
],
"product": "Archer AX55 v4",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.1 Build 20260527",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Tianchang Yang and Syed Rafiul Hussain (SyNSec Lab, Penn State University)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA\nstack-based buffer overflow vulnerability exists in the EasyMesh module of\nTP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit\ncrafted input that causes the easymesh daemon to crash and may potentially\nachieve remote code execution on the device.\u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation may cause the EasyMesh daemon to crash and may potentially allow\nremote code execution when Mesh mode is enabled. This\nmay result in high impact to the confidentiality, integrity, and availability\nof the affected device.\u003c/p\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e"
}
],
"value": "A\nstack-based buffer overflow vulnerability exists in the EasyMesh module of\nTP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit\ncrafted input that causes the easymesh daemon to crash and may potentially\nachieve remote code execution on the device.\n\n\n\n\n\nSuccessful\nexploitation may cause the EasyMesh daemon to crash and may potentially allow\nremote code execution when Mesh mode is enabled. This\nmay result in high impact to the confidentiality, integrity, and availability\nof the affected device."
}
],
"impacts": [
{
"capecId": "CAPEC-47",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-47 Buffer Overflow via Parameter Expansion"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "CWE-121 Stack-based buffer overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T22:24:57.369Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/archer-ax55/v4/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5279/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Stack-based buffer overflow in TP-Link Archer AX55 v4",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-18167",
"datePublished": "2026-09-03T22:24:57.369Z",
"dateReserved": "2026-07-28T20:48:04.039Z",
"dateUpdated": "2026-09-04T18:25:53.240Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-18330 (GCVE-0-2026-18330)
Vulnerability from cvelistv5 – Published: 2026-09-03 22:24 – Updated: 2026-09-04 18:25
VLAI
EPSS
VEX
Title
Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4
Summary
A hard-coded
cryptographic key vulnerability exists in the web module of TP-Link Archer
AX55 v4. A LAN attacker who captures an HTTP login session may use the known
shared RSA private key to decrypt the administrator password; the
weakened AES session key further reduces the effort required to
compromise session confidentiality.
Successful
exploitation may disclose the administrator password captured from an HTTP
login session and compromise session confidentiality.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-04 17:39 UTC
CWE
- CWE-321 - Use of hard-coded cryptographic key
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://www.tp-link.com/us/support/download/arche… | patch |
| https://www.tp-link.com/us/support/faq/5279/ | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| TP-Link Systems Inc. | Archer AX55 v4 |
Affected:
0 , < 1.2.1 Build 20260527
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-18330",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T17:39:51.418332Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T18:25:58.339Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"web"
],
"product": "Archer AX55 v4",
"vendor": "TP-Link Systems Inc.",
"versions": [
{
"lessThan": "1.2.1 Build 20260527",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Tianchang Yang and Syed Rafiul Hussain (SyNSec Lab, Penn State University)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA hard-coded\ncryptographic key vulnerability exists in the\u0026nbsp;web module of TP-Link Archer\nAX55 v4. A LAN attacker who captures an HTTP login session may use the known\nshared RSA private key to decrypt the\u0026nbsp;administrator\u0026nbsp;password; the\nweakened AES session key further reduces the effort\u0026nbsp;required\u0026nbsp;to\ncompromise session confidentiality.\u003c/p\u003e\n\n\u003cp\u003eSuccessful\nexploitation may disclose the administrator password captured from an HTTP\nlogin session and compromise session confidentiality.\u0026nbsp;\u003c/p\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e"
}
],
"value": "A hard-coded\ncryptographic key vulnerability exists in the\u00a0web module of TP-Link Archer\nAX55 v4. A LAN attacker who captures an HTTP login session may use the known\nshared RSA private key to decrypt the\u00a0administrator\u00a0password; the\nweakened AES session key further reduces the effort\u00a0required\u00a0to\ncompromise session confidentiality.\n\n\n\n\n\nSuccessful\nexploitation may disclose the administrator password captured from an HTTP\nlogin session and compromise session confidentiality."
}
],
"impacts": [
{
"capecId": "CAPEC-117",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-117 Interception"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-321",
"description": "CWE-321 Use of hard-coded cryptographic key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T22:24:45.430Z",
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://www.tp-link.com/us/support/download/archer-ax55/v4/#Firmware"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.tp-link.com/us/support/faq/5279/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"assignerShortName": "TPLink",
"cveId": "CVE-2026-18330",
"datePublished": "2026-09-03T22:24:45.430Z",
"dateReserved": "2026-07-29T20:03:53.524Z",
"dateUpdated": "2026-09-04T18:25:58.339Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}