Lucene search

K

TP-LINK Security Vulnerabilities

cve
cve

CVE-2017-15621

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the olmode variable in the interface_wan.lua...

7.2CVSS

7.4AI Score

0.001EPSS

2018-01-11 04:29 PM
21
cve
cve

CVE-2017-15623

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-enable variable in the pptp_server.lua...

7.2CVSS

7.4AI Score

0.001EPSS

2018-01-11 04:29 PM
24
cve
cve

CVE-2017-15626

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-bindif variable in the pptp_server.lua...

7.2CVSS

7.4AI Score

0.001EPSS

2018-01-11 04:29 PM
22
cve
cve

CVE-2017-15613

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-interface variable in the cmxddns.lua...

7.2CVSS

7.4AI Score

0.001EPSS

2018-01-11 04:29 PM
23
cve
cve

CVE-2017-15614

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-outif variable in the pptp_client.lua...

7.2CVSS

7.4AI Score

0.001EPSS

2018-01-11 04:29 PM
23
cve
cve

CVE-2017-15616

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-interface variable in the phddns.lua...

7.2CVSS

7.4AI Score

0.001EPSS

2018-01-11 04:29 PM
21
cve
cve

CVE-2017-15618

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-enable variable in the pptp_client.lua...

7.2CVSS

7.4AI Score

0.001EPSS

2018-01-11 04:29 PM
28
cve
cve

CVE-2017-17747

Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service...

6.5CVSS

6.4AI Score

0.002EPSS

2017-12-20 08:29 PM
24
cve
cve

CVE-2017-17745

Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName'...

5.4CVSS

5.3AI Score

0.001EPSS

2017-12-20 08:29 PM
23
cve
cve

CVE-2017-17746

Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials. The authentication record is stored on the device; thus if an administrator authenticates from a NAT network, the...

6.8CVSS

6.6AI Score

0.0004EPSS

2017-12-20 08:29 PM
21
cve
cve

CVE-2017-17758

TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/dhcps command to cgi-bin/luci, related to the zone_get_iface_bydev function in /usr/lib/lua/luci/controller/admin/dhcps.lua in...

8.8CVSS

8.8AI Score

0.002EPSS

2017-12-19 07:29 AM
18
cve
cve

CVE-2017-17757

TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/wportal.lua in...

8.8CVSS

8.8AI Score

0.002EPSS

2017-12-19 07:29 AM
19
cve
cve

CVE-2017-16959

The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP...

6.5CVSS

6.3AI Score

0.048EPSS

2017-11-27 10:29 AM
23
cve
cve

CVE-2017-16958

TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/bridge.lua in...

8.8CVSS

8.8AI Score

0.004EPSS

2017-11-27 10:29 AM
27
cve
cve

CVE-2017-16960

TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/interface.lua...

8.8CVSS

8.8AI Score

0.001EPSS

2017-11-27 10:29 AM
25
cve
cve

CVE-2017-16957

TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zone_get_effect_devices function in...

8.8CVSS

8.8AI Score

0.002EPSS

2017-11-27 10:29 AM
34
cve
cve

CVE-2017-13772

Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to...

8.8CVSS

8.7AI Score

0.697EPSS

2017-10-23 06:29 PM
89
2
cve
cve

CVE-2017-15291

Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject arbitrary web script or HTML via the Description...

6.1CVSS

6AI Score

0.001EPSS

2017-10-20 05:29 PM
36
cve
cve

CVE-2017-10796

On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:554/h264_hd.sdp...

6.5CVSS

6.7AI Score

0.001EPSS

2017-07-02 10:29 PM
26
2
cve
cve

CVE-2017-9466

The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption. This resulted in incorrect access control, which allowed attackers to gain read-write access to system settings through the protected router...

9.8CVSS

9.4AI Score

0.003EPSS

2017-06-26 07:29 AM
23
cve
cve

CVE-2017-8075

On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext. This affects the 1.1.2 Build 20141017 Rel.50749...

9.8CVSS

9.2AI Score

0.004EPSS

2017-04-23 04:59 PM
19
cve
cve

CVE-2017-8078

On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd). This affects the 1.1.2 Build 20141017 Rel.50749...

5.3CVSS

5.4AI Score

0.001EPSS

2017-04-23 04:59 PM
18
cve
cve

CVE-2017-8074

On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadecimal. This affects the 1.1.2 Build 20141017 Rel.50749...

9.8CVSS

9.2AI Score

0.015EPSS

2017-04-23 04:59 PM
18
cve
cve

CVE-2016-1000009

TP-LINK lost control of two domains, www.tplinklogin.net and tplinkextender.net. Please note that these domains are physically printed on many of the...

7.5CVSS

7.6AI Score

0.001EPSS

2016-10-06 02:59 PM
18
cve
cve

CVE-2015-3035

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and...

8.9AI Score

0.59EPSS

2015-04-22 01:59 AM
839
In Wild
cve
cve

CVE-2014-9510

Cross-site request forgery (CSRF) vulnerability in the administration console in TP-Link TL-WR840N (V1) router with firmware before 3.13.27 build 141120 allows remote attackers to hijack the authentication of administrators for requests that change router settings via a configuration file...

7.4AI Score

0.002EPSS

2015-01-09 06:59 PM
15
cve
cve

CVE-2014-9350

TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a denial of service (httpd crash) via vectors involving a "new" value in the isNew parameter to...

6.8AI Score

0.516EPSS

2014-12-08 04:59 PM
21
cve
cve

CVE-2013-2645

Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_120405 allow remote attackers to hijack the authentication of administrators for requests that (1) enable FTP access (aka "FTP directory traversal") to /tmp via the shareEntire...

7.7AI Score

0.003EPSS

2014-10-06 01:55 AM
22
cve
cve

CVE-2014-4728

The web server in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to cause a denial of service (crash) via a long header in a GET...

6.8AI Score

0.022EPSS

2014-09-30 04:55 PM
19
cve
cve

CVE-2014-4727

Cross-site scripting (XSS) vulnerability in the DHCP clients page in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to inject arbitrary web script or HTML via the hostname in a DHCP...

5.8AI Score

0.004EPSS

2014-09-30 04:55 PM
21
cve
cve

CVE-2012-6316

Multiple cross-site scripting (XSS) vulnerabilities in the TP-LINK TL-WR841N router with firmware 3.13.9 Build 120201 Rel.54965n and earlier allow remote administrators to inject arbitrary web script or HTML via the (1) username or (2) pwd parameter to...

5.9AI Score

0.001EPSS

2014-09-30 02:55 PM
19
cve
cve

CVE-2012-5687

Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/...

6.7AI Score

0.03EPSS

2012-11-01 10:44 AM
44
cve
cve

CVE-2012-2440

The default configuration of the TP-Link 8840T router enables web-based administration on the WAN interface, which allows remote attackers to establish an HTTP connection and possibly have unspecified other impact via unknown...

7.5AI Score

0.006EPSS

2012-04-28 12:55 AM
21
Total number of security vulnerabilities383