Vulnerabilities
Vulnerable Software
Tp-Link:  Security Vulnerabilities
The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).
CVSS Score
8.7
EPSS Score
0.004
Published
2025-12-20
The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests to trigger excessive memory allocation, causing the device to crash and resulting in denial-of-service (DoS).
CVSS Score
7.1
EPSS Score
0.002
Published
2025-12-20
Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922.
CVSS Score
7.1
EPSS Score
0.009
Published
2025-12-18
Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922.
CVSS Score
5.7
EPSS Score
0.004
Published
2025-12-18
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
CVSS Score
9.3
EPSS Score
0.01
Published
2025-10-21
A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
CVSS Score
9.3
EPSS Score
0.033
Published
2025-10-21
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
CVSS Score
8.7
EPSS Score
0.007
Published
2025-10-21
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
CVSS Score
8.6
EPSS Score
0.007
Published
2025-10-21
CVE-2025-9377
Known exploited
The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's recommending to purchase the new product to ensure better performance and security. If replacement is not an option in the short term, please use the second reference link to download and install the patch(es).
CVSS Score
8.6
EPSS Score
0.335
Published
2025-08-29
The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off condition and potential information leak. This issue affects TP-Link KP303 (US) Smartplug: before 1.1.0.
CVSS Score
8.7
EPSS Score
0.003
Published
2025-08-25


Contact Us

Shodan ® - All rights reserved