Vulnerabilidades em TP-Link Systems Inc.

139 resultados
Análise Vexday

Com 121 CVEs catalogadas, os dispositivos TP-Link Systems Inc. apresentam taxa de exploração ativa 1,8× acima da média geral do catálogo CISA KEV, o que indica que vulnerabilidades nesse portfólio têm sido alvo de agentes maliciosos em proporção elevada. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria que facilita execução remota de código e tende a ser explorada com relativa facilidade. O CVE mais crítico em exploração ativa no momento é CVE-2025-9377, com EPSS de 0,1175, e o surgimento de 33 novas CVEs nos últimos 90 dias sinaliza um ritmo recente de descobertas que merece acompanhamento contínuo. Equipes responsáveis por ativos TP-Link devem priorizar a aplicação de patches, especialmente em equipamentos expostos à internet, dada a combinação de exploração ativa confirmada e a prevalência de falhas de injeção de comandos.

CVE-2026-0630HIGHCommand Injection Vulnerability on TP-Link Archer BE230 v1.2 and AXE75 v1.0EPSS 1.3%CVE-2026-22221HIGHCommand Injection Vulnerability on TP-Link Archer BE230 v1.2EPSS 1.3%CVE-2026-0631HIGHCommand Injection Vulnerability on Archer BE230 + OpenVPN of AXE75EPSS 1.3%CVE-2026-30818HIGHOS Command Injection Vulnerability in dnsmasq Module in TP-Link AX53EPSS 1.2%CVE-2026-30815HIGHOS Command Injection Vulnerability in OpenVPN Module in TP-Link AX53EPSS 1.2%CVE-2026-3227HIGHAuthenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840NEPSS 1.1%CVE-2026-9151HIGHCommand Injection Vulnerability in OpenVPN on Multiple TP-Link Archer RoutersEPSS 1.1%CVE-2026-11834HIGHUnauthenticated Command Injection via DHCP Option Handling in Multiple TP-Link RoutersEPSS 1.0%CVE-2025-14737HIGHCommand Injection Vulnerability in TP-Link WA850REEPSS 1.0%CVE-2026-1668HIGHInput Validation Vulnerability on Multiple Omada SwitchesEPSS 1.0%CVE-2025-6542CRITICALOS command injection in multiple parametersEPSS 0.9%CVE-2026-8913HIGHCommand Injection in TP-Link's Archer MR600 WireGuard Client ConfigurationEPSS 0.9%CVE-2025-7724HIGHUnauthenticated command injection on VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2EPSS 0.9%CVE-2026-15428HIGHOS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800vEPSS 0.9%CVE-2026-12935HIGHUnauthenticated Remote Code Execution in TP-Link TL-WR940N RTSP Conntrack FeatureEPSS 0.8%CVE-2026-9105MEDIUMAuthenticated Stack-Based Buffer Overflow in TP-Link TL-WR841N Web InterfaceEPSS 0.8%CVE-2025-7723HIGHAuthenticated command injection on VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2EPSS 0.8%CVE-2026-0918HIGHNull Pointer Dereference in Tapo SmartCam HTTP Service on TP-Link Tapo C220 & C520WSEPSS 0.7%CVE-2025-6541HIGHOS command injection using information obtained from the web management interfaceEPSS 0.7%CVE-2025-15608HIGHBuffer Overflow in Network Probe Handling Function of TP-Link Archer AX53 + Archer AX55EPSS 0.6%