Vulnerabilities > TP Link > Low

DATE CVE VULNERABILITY TITLE RISK
2018-10-01 CVE-2018-15701 Improper Input Validation vulnerability in Tp-Link Tl-Wrn841N Firmware 0.9.14.16V0348.0
The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated LAN user sends a crafted HTTP header containing an unexpected Cookie field.
low complexity
tp-link CWE-20
3.3
2018-05-03 CVE-2018-10164 Cross-site Scripting vulnerability in Tp-Link EAP Controller 2.5.4/2.6.0
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implementation of portalPictureUpload functionality.
network
tp-link CWE-79
3.5
2018-05-03 CVE-2018-10165 Cross-site Scripting vulnerability in Tp-Link EAP Controller 2.5.4/2.6.0
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the userName parameter in the local user creation functionality.
network
tp-link CWE-79
3.5
2017-12-20 CVE-2017-17745 Cross-site Scripting vulnerability in Tp-Link Tl-Sg108E Firmware 1.0.0
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName' parameter.
network
tp-link CWE-79
3.5
2017-12-20 CVE-2017-17747 Missing Authentication for Critical Function vulnerability in Tp-Link Tl-Sg108E Firmware 1.0.0
Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service condition.
low complexity
tp-link CWE-306
2.7
2017-07-02 CVE-2017-10796 Improper Authentication vulnerability in Tp-Link Nc250 Firmware
On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:554/h264_hd.sdp URL.
low complexity
tp-link CWE-287
3.3