Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.92% | — | Tp-link Tl-wr841nAI | 1/10/2026 | 2/10/2026 | TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands. Successful exploitation may allow… | |
| Aplazada | Media (5.3) | 0.44% | — | Tp-link Tl-wr841nAI | 28/8/2026 | 1/9/2026 | A buffer overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing multipart/form-data requests. Insufficient validation of an attacker-controlled boundary parameter may allow a remote unauthenticated attacker to submit a crafted request that corrupts memory by overwriting data beyond… | |
| Aplazada | Media (5.3) | 0.27% | — | Tp-link Tl-wr841nAI | 28/8/2026 | 1/9/2026 | A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP state variable query requests. A specially crafted SOAP query may trigger unexpected termination or instability of the process hosting the UPnP service. Successful exploitation may result in a denial-of-service… | |
| Analizada | Media (6.8) | 1.1% | — | Tp-link Tl-wr841n Firmware | 29/6/2026 | 1/7/2026 | An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests to cause the embedded web server to overflow a stack buffer, resulting in a crash of the affected process. Successful exploitation… | |
| Analizada | Media (6.1) | 0.21% | — | Tp-link Tl-wr841n Firmware | 23/4/2026 | 17/6/2026 | TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default web management credentials, making the key predictable if device is left in default configuration. A network-adjacent attacker can exploit this weakness to gain unauthorized access to the protocol,… | |
| Analizada | Alta (7.1) | 0.70% | — | Tp-link Tl-wr841n Firmware | 26/3/2026 | 17/6/2026 | The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-bounds read, potentially causing a crash of the UPnP service. Successful exploitation can cause the UPnP service to crash, resulting in a Denial-of-Service condition. This vulnerability affects TL-WR841N… | |
| Analizada | Alta (8.5) | 1.8% | 💥 PoC | Tp-link Tl-wr802n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr840n Firmware | 16/3/2026 | 1/7/2026 | A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in… | |
| Analizada | Media (6.3) | 0.50% | — | Tp-link Tl-wr841n Firmware | 15/1/2026 | 17/6/2026 | A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input validation. A remote, unauthenticated attacker can exploit this flaw and cause Denial of Service on the web portal service.This issue affects TL-WR841N v14: before 250908. | |
| Analizada | Alta (8.6) | 34% | ⚠ Explotación activa | Tp-link Tl-wr841n FirmwareTp-link Tl-wr841nd FirmwareTp-link Archer C7 Firmware | 29/8/2025 | 17/6/2026 | The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's… | |
| Analizada | Media (6.9) | 0.31% | — | Tp-link Tl-wr841n Firmware | 29/7/2025 | 17/6/2026 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/Wan6to4TunnelCfgRpm.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS) condition. The attack may be… | |
| Analizada | Media (6.9) | 0.31% | — | Tp-link Tl-wr841n Firmware | 29/7/2025 | 17/6/2026 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WzdWlanSiteSurveyRpm_AP.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS) condition. The attack may be… | |
| Analizada | Media (6.9) | 0.31% | — | Tp-link Tl-wr841n Firmware | 29/7/2025 | 17/6/2026 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_APC.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS) condition. The attack may be… | |
| Analizada | Media (6.9) | 0.31% | — | Tp-link Tl-wr841n Firmware | 29/7/2025 | 17/6/2026 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_AP.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS) condition. The attack may be launched… | |
| Modificada | Media (6.9) | 0.31% | — | Tp-link Tl-wr841n Firmware | 29/7/2025 | 17/6/2026 | A vulnerability has been found in TP-Link TL-WR841N v11, TL-WR842ND v2 and TL-WR494N v3. The vulnerability exists in the /userRpm/WlanNetworkRpm.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS)… | |
| Modificada | Alta (7.5) | 0.52% | — | Tp-link Tl-wr841nd Firmware | 13/2/2025 | 17/6/2026 | A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11, triggered by the dnsserver1 and dnsserver2 parameters at /userRpm/WanSlaacCfgRpm.htm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet. | |
| Analizada | Media (4.9) | 0.42% | — | Tp-link Tl-wr841nd V11 Firmware | 13/2/2025 | 17/6/2026 | A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the username and password parameters at /userRpm/PPPoEv6CfgRpm.htm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet. | |
| Analizada | Baja (3.5) | 0.31% | — | Tp-link Tl-wr841nd V11 Firmware | 13/2/2025 | 17/6/2026 | A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'gw' parameter at /userRpm/WanDynamicIpV6CfgRpm.htm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet. | |
| Modificada | Alta (7.5) | 0.52% | — | Tp-link Tl-wr841nd Firmware | 13/2/2025 | 17/6/2026 | A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the pskSecret parameter at /userRpm/WlanSecurityRpm.htm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet. | |
| Modificada | Alta (7.5) | 0.52% | — | Tp-link Tl-wr841nd Firmware | 13/2/2025 | 17/6/2026 | A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'ip' parameter at /userRpm/WanStaticIpV6CfgRpm.htm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet. | |
| Analizada | Alta (7.1) | 0.98% | — | Tp-link Tl-wr841nd Firmware | 27/9/2024 | 17/6/2026 | A vulnerability was found in TP-LINK TL-WR841ND up to 20240920. It has been rated as critical. Affected by this issue is some unknown functionality of the file /userRpm/popupSiteSurveyRpm.htm. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack may be launched remotely. The exploit… | |
| Analizada | Media (6.5) | 16% | ⚠ Explotación activa | Tp-link Tl-wr841n FirmwareTp-link Mr6400 FirmwareTp-link Tl-wdr3600 FirmwareTp-link Tl-wdr4300 Firmware+32 | 3/5/2024 | 3/9/2026 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (8.8) | 0.91% | — | Tp-link Tl-wr841n FirmwareTp-link Tl-wr840n Firmware | 3/5/2024 | 17/6/2026 | TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Alta (8.8) | 0.56% | — | Tp-link Tl-wr902ac FirmwareTp-link Tl-wr802n FirmwareTp-link Tl-wr841n Firmware | 6/9/2023 | 17/6/2026 | Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: TL-WR802N firmware versions prior to 'TL-WR802N(JP)_V4_221008', TL-WR841N firmware versions prior to 'TL-WR841N(JP)_V14_230506', and TL-WR902AC firmware versions… | |
| Modificada | Crítica (9.8) | 8.7% | — | Tp-link Tl-wr940n V2 FirmwareTp-link Tl-wr941nd V5 FirmwareTp-link Tl-wr841n V8 Firmware | 21/8/2023 | 17/6/2026 | TP-Link WR841N V8, TP-Link TL-WR940N V2, and TL-WR941ND V5 were discovered to contain a buffer overflow via the radiusSecret parameter at /userRpm/WlanSecurityRpm. | |
| Modificada | Alta (7.5) | 0.74% | — | Tp-link Tl-wr940n V2 FirmwareTp-link Tl-wr941nd V5 FirmwareTp-link Tl-wr841n V8 Firmware | 21/8/2023 | 17/6/2026 | TP-Link TL-WR940N V2, TP-Link TL-WR941ND V5 and TP-Link TL-WR841N V8 were discovered to contain a buffer overflow via the component /userRpm/AccessCtrlAccessRulesRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. |