Known Vulnerabilities for products from TP-Link

Listed below are 20 of the newest known vulnerabilities associated with the vendor "TP-Link".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by TP-Link can be found at device.report : TP-Link

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-89240 json Not Provided 2026-09-11 2026-09-11
CVE-2026-89049 json Not Provided 2026-09-10 2026-09-10
CVE-2026-88924 json Not Provided 2026-09-10 2026-09-11
CVE-2026-88893 json Not Provided 2026-09-10 2026-09-10
CVE-2026-88887 json Not Provided 2026-09-10 2026-09-10
CVE-2026-88882 json Not Provided 2026-09-10 2026-09-10
CVE-2026-88881 json Not Provided 2026-09-10 2026-09-10
CVE-2026-88880 json Not Provided 2026-09-10 2026-09-10
CVE-2026-88868 json Not Provided 2026-09-10 2026-09-10
CVE-2026-87910 json Not Provided 2026-09-11 2026-09-11
CVE-2026-75619 json Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the l... Not Provided 2026-08-19 2026-09-04
CVE-2026-75618 json Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can... Not Provided 2026-08-19 2026-09-04
CVE-2026-75616 json An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certai... Not Provided 2026-08-19 2026-09-08
CVE-2026-34127 json A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE... Not Provided 2026-05-29 2026-07-22
CVE-2026-34126 json TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth comm... Not Provided 2026-05-28 2026-06-03
CVE-2026-34124 json A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The ... Not Provided 2026-04-02 2026-07-24
CVE-2026-34122 json A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling compon... Not Provided 2026-04-02 2026-07-24
CVE-2026-34121 json An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 w... Not Provided 2026-04-02 2026-07-24
CVE-2026-34120 json A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing of loca... Not Provided 2026-04-02 2026-07-24
CVE-2026-34119 json A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when appen... Not Provided 2026-04-02 2026-07-24

Known software with vulnerabilities from TP-Link

Type Vendor Product Version
HardwareTp-linkAc1750-
Operating
System
Tp-linkAc1750 Firmware190726
HardwareTp-linkArcher A7v5
Operating
System
Tp-linkArcher A7 Firmware200721
Operating
System
Tp-linkArcher C1200 Firmware1.0.0
HardwareTp-linkArcher C50 V3-
Operating
System
Tp-linkArcher C50 V3 Firmware170822
Operating
System
Tp-linkArcher C5 Firmware-
HardwareTp-linkArcher C5 1.2-
Operating
System
Tp-linkArcher C5 1.2 Firmware141126
HardwareTp-linkArcher C7-
Operating
System
Tp-linkArcher C7 Firmware-
HardwareTp-linkArcher C7 2.0-
Operating
System
Tp-linkArcher C7 2.0 Firmware141110
HardwareTp-linkArcher C8 1.0-
Operating
System
Tp-linkArcher C8 1.0 Firmware141023
HardwareTp-linkArcher C9v1
Operating
System
Tp-linkArcher C9 Firmware180125
HardwareTp-linkArcher C9 1.0-
Operating
System
Tp-linkArcher C9 1.0 Firmware150122

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report