Tp-link-systems-inc
165 CVEs tracked since 2025. Since Jul 2025, none of them reached CISA KEV.
Tp-link-systems-inc CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-07 | 8 | 0 |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | 8 | 0 |
| 2026-01 | 21 | 0 |
| 2026-02 | 30 | 0 |
| 2026-03 | 16 | 0 |
| 2026-04 | 13 | 0 |
| 2026-05 | null or fewer | |
| 2026-06 | 16 | 0 |
| 2026-07 | 10 | 0 |
| 2026-08 | 35 | 0 |
| 2026-09 | 8 | 0 |
Products
The products that kept showing up in Tp-link-systems-inc's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Tp-link-systems-inc.
- CVE-2026-84941Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read—
- CVE-2026-17176OS command injection Vulnerability in Deco BE11000—
- CVE-2026-76652Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600—
- CVE-2026-76653Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR600—
- CVE-2026-85384Authenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration Import—
- CVE-2026-81531Unauthenticated Account Information Disclosure in Multiple Omada Controllers—
- CVE-2026-18167Stack-based buffer overflow in TP-Link Archer AX55 v4—
- CVE-2026-18330Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4—
- CVE-2026-75118http_gdpr_decrypt Pre-Authentication Stack-Based Buffer Overflow—
- CVE-2026-76784Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices—
- CVE-2026-78541Command Injection in Parent Control of TP-Link Archer BE3600 v1—
- CVE-2026-16348Command Injection Vulnerability in VPN connection of Archer BE800—
- CVE-2026-9254Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices—
- CVE-2026-15469Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800—
- CVE-2026-17252Unauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based Out-of-Bounds Write Vulnerability in TL-MR6400 Web Management Interface—
The record
- Peak rank
- #28 in Feb 2026
- Busiest month shown
- Aug 2026, 35 CVEs
- Months with a KEV entry
- 0 since Jul 2025
- Monthly snapshots
- 10 since 2025