TP-Link Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for TP-Link products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

9

In CISA KEV

6

Beyond CISA KEV

3

Sensor Observed

1

Virtual Patch Available

1

TP-Link KEVs Added by Year

Loading...

9 TP-Link KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2018-11714

An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0...

High Not in CISA 26 Jan 2026
CVE-2021-41653

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a...

High Not in CISA 18 Sep 2025
CVE-2025-9377

Authenticated RCE via Parental Control command injection

Confirmed In CISA 01 Jun 2026
CVE-2023-50224

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2020-24363

TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a...

Confirmed In CISA 01 Jun 2026
CVE-2023-33538

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component...

Confirmed In CISA 01 Jun 2026
CVE-2015-3035

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with...

Confirmed In CISA 25 Mar 2022
CVE-2023-1389

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the...

Confirmed In CISA 01 May 2023
CVE-2017-16959

The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence...

High Not in CISA 27 Nov 2017

Common Vulnerability Classes (CWE)

  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 2
  • CWE-306 — Missing Authentication for Critical Function 1
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
  • CWE-384 — Session Fixation 1
  • CWE-290 — Authentication Bypass by Spoofing 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology