| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.
Successful exploitation may allow arbitrary command execution, potentially
leading to full compromise of the affected device. |
| Tapo C120 v1 and C200 v5
contain an improper authentication vulnerability within the login
authentication verification module. An attacker on the local network can
exploit weaknesses in challenge parameter validation to bypass normal
authentication controls and obtain administrative session tokens.
Successful
exploitation may allow an attacker to subsequently execute privileged
management actions, enable unauthorized administrative access and temporary
disruption of device services, resulting in a denial-of-service (DoS)
condition. |
| A Zip Slip vulnerability in the WebUI ISP
Upgrade functionality allows arbitrary file write via a crafted archive
containing directory traversal sequences. An authenticated administrator may
overwrite arbitrary files on the system.Successful
exploitation may allow arbitrary file to be overwritten on the underlying system, affecting system integrity and availability. |
| The use of
hard-coded cryptographic key vulnerability has been identified in the mesh
functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6.
A shared RSA-512 mesh group private key is present in the affected
firmware and is used by the mesh protocol for node authentication. An attacker who obtains the firmware image
and has local network access may be able to authenticate as a mesh node without
possessing a device-specific credential.
Successful
exploitation may allow an unauthenticated adjacent attacker to impersonate a
trusted mesh node and bypass mesh node authentication, which may permit unauthorized
changes to device or mesh configuration, affecting confidentiality, integrity
and availability. |
| An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges.
Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic. |
| An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.
Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices. |
| A stored OS
command injection vulnerability exists in the parent-control module of TP-Link
Archer BE3600 V1. An authenticated adjacent attacker with administrative access
may store a crafted profile name containing shell metacharacters, which is
later processed unsafely during daily cloud report generation and may result in
arbitrary command execution.
Successful
exploitation may allow command execution on the affected device with potential
impact to device confidentiality, integrity, and availability. |
| An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation to execute arbitrary system commands, potentially resulting in full device compromise.
Successful exploitation may allow arbitrary command execution with elevated privileges, compromising the confidentiality, integrity, and availability of the affected device and network traffic passing through it. |
| A
stack-based buffer overflow vulnerability exists in the firmware update
functionality of TL-MR6400 v7 due to unsafe processing of
attacker-controlled metadata within a firmware image.
Successful
exploitation may allow an authenticated attacker to trigger memory corruption
and execute arbitrary code on the affected device. |
| An improper input
validation vulnerability in the configuration service for processing encrypted
credential data has been identified in Tapo C200 v5. An attacker can send oversized crypted
ciphertext values that may trigger exception handling failures, due to insufficient
validation, causing the affected device to crash or restart.
Successful
exploitation may temporarily disrupt HTTPS management and monitoring
functionality, resulting in a denial-of-service (DoS) condition until the
service recovers. |
| A NULL
pointer dereference vulnerability exists in the HTTP request parsing
functionality of
TL-MR6400 v7. An unauthenticated remote attacker can
trigger the vulnerability by sending a specially crafted HTTP request
containing a malformed session cookie header.
Successful
exploitation may cause the HTTP service process to crash, resulting in a
denial-of-service condition and temporary loss of management or CGI
functionality until service recovery. |
| A
stack-based out-of-bounds write vulnerability exists in the login request
handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability
by sending a specially crafted malformed HTTP request.
Successful
exploitation may cause the web service process to crash, resulting in a
denial-of-service condition and temporary loss of access to the router's web
management interface. |
| An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access.
Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate. |
| A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path.
Successful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment. |
| Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful exploitation can disrupt live video streaming functionality and cause a temporary denial-of-service condition. |
| Tapo
C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP
service. An authenticated attacker on the local network can send specially
crafted RTSP frame data containing oversized length values, resulting in
out-of-bounds heap writes.
Successful
exploitation can crash the RTSP service and trigger a device reboot, resulting
in a temporary denial-of-service condition. |
| A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to insufficient boundary validation when handling externally supplied HTTP input.
An attacker
on the same network segment could trigger heap memory corruption conditions by
sending crafted payloads that cause write operations beyond allocated buffer
boundaries. Successful exploitation
causes a Denial-of-Service (DoS) condition, causing the device’s process to
crash or become unresponsive. |
| The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS). |
| The web
interface of the affected
device relies on the HTTP referrer header as part of
request validation. Requests containing empty Referer value, or omitting
the Referer header entirely, may be accepted and processed due to insufficient
validation logic.
Successful exploitation may allow an adjacent attacker with access to the web management
interface to obtain device configuration details and other sensitive
information. |
| The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage
devices. By placing a crafted symbolic link on supported storage media, an
attacker may cause the system to resolve the link.
Successful
exploitation may allow unauthorized read access to sensitive files within the
device filesystem. |