Brand
TP-Link: actively exploited vulnerabilities
6 vulnerabilities in TP-Link products (Archer (Wi-Fi routers), TL-WR (Wi-Fi routers), Range extenders and access points (TL-WA, RE)) are in CISA’s catalog of exploited vulnerabilities. Last added: September 3, 2025.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
0 vulnerabilities added in the last 12 months
-
6 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one TP-Link category to your radar, or open its page.
- Home and small-office routers, cameras and IoT 6 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
Follow a single TP-Link product (Archer (Wi-Fi routers), TL-WR (Wi-Fi routers)…) rather than the whole brand.
- Archer (Wi-Fi routers)3 vulnerabilities, Home routers and IoT
- TL-WR (Wi-Fi routers)2 vulnerabilities, Home routers and IoT
- Range extenders and access points (TL-WA, RE)1 vulnerability, Home routers and IoT
Name used by CISA: TP-Link. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this TP-Link list.
- Rank 1
TP-Link Range extenders and access points (TL-WA, RE)CVE-2020-24363
TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability
CVE from 2020, added in 2025
CVSS severity 8.8high
Added Sep 2, 2025
- Rank 2
TP-Link TL-WR (Wi-Fi routers)CVE-2023-33538
TP-Link Multiple Routers Command Injection Vulnerability
CVE from 2023, added in 2025
CVSS severity 8.8high
Added Jun 16, 2025
- Rank 3
TP-Link Archer (Wi-Fi routers)CVE-2023-1389
TP-Link Archer AX-21 Command Injection Vulnerability
CVSS severity 8.8high
Added May 1, 2023
- Rank 4
TP-Link Archer (Wi-Fi routers)CVE-2015-3035
TP-Link Multiple Archer Devices Directory Traversal Vulnerability
CVE from 2015, added in 2022
CVSS severity 7.5high
Added Mar 25, 2022
- Rank 5
TP-Link Archer (Wi-Fi routers)CVE-2025-9377
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
CVSS severity 7.2high
Added Sep 3, 2025
- Rank 6
TP-Link TL-WR (Wi-Fi routers)CVE-2023-50224
TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
CVE from 2023, added in 2025
CVSS severity 6.5medium
Added Sep 3, 2025
Follow and verify
Get new TP-Link vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.