Vulnerabilities > TP Link > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-05-30 CVE-2018-11482 Use of Hard-coded Credentials vulnerability in Tp-Link products
/usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 password.
network
low complexity
tp-link CWE-798
critical
9.8
2017-07-21 CVE-2017-11519 Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Tp-Link Archer C9 (2.0) Firmware 160517
passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random number generator seed.
network
low complexity
tp-link CWE-335
critical
9.8
2017-06-26 CVE-2017-9466 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Tp-Link Wr841N V8 Firmware Tlwr841Nv8140724
The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption.
network
low complexity
tp-link CWE-327
critical
9.8
2017-04-25 CVE-2017-8220 OS Command Injection vulnerability in Tp-Link C20I Firmware and C2 Firmware
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by placing shell commands in a "host=" line within HTTP POST data.
network
low complexity
tp-link CWE-78
critical
9.9
2017-04-25 CVE-2017-8218 Insecure Default Initialization of Resource vulnerability in Tp-Link C20I Firmware and C2 Firmware
vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n has a backdoor admin account with the 1234 password, a backdoor guest account with the guest password, and a backdoor test account with the test password.
network
low complexity
tp-link CWE-1188
critical
9.8
2017-04-23 CVE-2017-8076 Inadequate Encryption Strength vulnerability in Tp-Link Tl-Sg108E Firmware 1.1.2
On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is deprecated.
network
low complexity
tp-link CWE-326
critical
9.8
2017-04-23 CVE-2017-8075 Information Exposure Through Log Files vulnerability in Tp-Link Tl-Sg108E Firmware 1.1.2
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext.
network
low complexity
tp-link CWE-532
critical
9.8
2017-04-23 CVE-2017-8074 Information Exposure Through Log Files vulnerability in Tp-Link Tl-Sg108E Firmware 1.1.2
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadecimal.
network
low complexity
tp-link CWE-532
critical
9.8