FR
live
vendor

Tp-link

5
vulnerabilities tracked
4 August 2026
latest publication
cve

Vulnerability watch

idvulnerabilityseveritypublished
CVE-2026-15314Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash. Successful exploitation may cause the web service process to stop responding or restart, resulting in a denial-of-service condition.Tp-link Tapo P110 Firmware High CVSS 7.5 04/08 CVE-2025-15627A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications.Tp-link Omada Oc200 V3 Firmware High CVSS 7.5 03/08 CVE-2025-15628Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications.Tp-link Omada Oc200 V3 Firmware High CVSS 7.5 03/08 CVE-2025-15629A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be able to recover session encryption keys and decrypt affected communications.Tp-link Omada Oc200 V3 Firmware High CVSS 7.5 03/08 CVE-2026-9044An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters.  Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability.Tp-link Archer Axe75 Firmware High CVSS 8 31/07

Type at least two characters.

navigate open esc dismiss