Vulnerabilities > TP Link > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-01 CVE-2024-22733 NULL Pointer Dereference vulnerability in Tp-Link Mr200 Firmware 210201
TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on /cgi/login via the sign, Action or LoginStatus query parameters which could lead to a denial of service by a local or remote unauthenticated attacker.
network
low complexity
tp-link CWE-476
7.5
2024-03-06 CVE-2023-43318 Unspecified vulnerability in Tp-Link Tl-Sg2210P Firmware 5.0
TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.
network
low complexity
tp-link
8.8
2024-02-06 CVE-2023-36498 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2
2024-02-06 CVE-2023-42664 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2
2024-02-06 CVE-2023-43482 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2
2024-02-06 CVE-2023-46683 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2
2024-02-06 CVE-2023-47167 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2
2024-02-06 CVE-2023-47209 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2
2024-02-06 CVE-2023-47617 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2
2024-02-06 CVE-2023-47618 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2