Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 1.1% | — | Tp-link Tl-wr841n Firmware | 29/6/2026 | 1/7/2026 | An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests to cause the embedded web server to overflow a stack buffer, resulting in a crash of the affected process. Successful exploitation… | |
| Analizada | Media (6.1) | 0.21% | — | Tp-link Tl-wr841n Firmware | 23/4/2026 | 17/6/2026 | TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default web management credentials, making the key predictable if device is left in default configuration. A network-adjacent attacker can exploit this weakness to gain unauthorized access to the protocol,… | |
| Analizada | Alta (7.1) | 0.70% | — | Tp-link Tl-wr841n Firmware | 26/3/2026 | 17/6/2026 | The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-bounds read, potentially causing a crash of the UPnP service. Successful exploitation can cause the UPnP service to crash, resulting in a Denial-of-Service condition. This vulnerability affects TL-WR841N… | |
| Analizada | Alta (8.5) | 1.8% | 💥 PoC | Tp-link Tl-wr802n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr840n Firmware | 16/3/2026 | 1/7/2026 | A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in… | |
| Analizada | Media (6.3) | 0.50% | — | Tp-link Tl-wr841n Firmware | 15/1/2026 | 17/6/2026 | A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input validation. A remote, unauthenticated attacker can exploit this flaw and cause Denial of Service on the web portal service.This issue affects TL-WR841N v14: before 250908. | |
| Analizada | Alta (8.6) | 36% | ⚠ Explotación activa | Tp-link Tl-wr841n FirmwareTp-link Tl-wr841nd FirmwareTp-link Archer C7 Firmware | 29/8/2025 | 17/6/2026 | The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's… | |
| Analizada | Media (6.9) | 0.31% | — | Tp-link Tl-wr841n Firmware | 29/7/2025 | 17/6/2026 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/Wan6to4TunnelCfgRpm.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS) condition. The attack may be… | |
| Analizada | Media (6.9) | 0.31% | — | Tp-link Tl-wr841n Firmware | 29/7/2025 | 17/6/2026 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WzdWlanSiteSurveyRpm_AP.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS) condition. The attack may be… | |
| Analizada | Media (6.9) | 0.31% | — | Tp-link Tl-wr841n Firmware | 29/7/2025 | 17/6/2026 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_APC.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS) condition. The attack may be… | |
| Analizada | Media (6.9) | 0.31% | — | Tp-link Tl-wr841n Firmware | 29/7/2025 | 17/6/2026 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_AP.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS) condition. The attack may be launched… | |
| Modificada | Media (6.9) | 0.31% | — | Tp-link Tl-wr841n Firmware | 29/7/2025 | 17/6/2026 | A vulnerability has been found in TP-Link TL-WR841N v11, TL-WR842ND v2 and TL-WR494N v3. The vulnerability exists in the /userRpm/WlanNetworkRpm.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS)… | |
| Analizada | Alta (8.6) | 0.58% | — | Tp-link Wr841n Firmware | 18/4/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/v14.8 <= Build 241230 Rel. 50788n allows remote attackers to inject arbitrary JavaScript code via the port mapping description. This leads to an execution of the JavaScript payload when the upnp page… | |
| Analizada | Media (6.5) | 16% | ⚠ Explotación activa | Tp-link Tl-wr841n FirmwareTp-link Mr6400 FirmwareTp-link Tl-wdr3600 FirmwareTp-link Tl-wdr4300 Firmware+32 | 3/5/2024 | 3/9/2026 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (8.8) | 0.91% | — | Tp-link Tl-wr841n FirmwareTp-link Tl-wr840n Firmware | 3/5/2024 | 17/6/2026 | TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Alta (8.8) | 0.56% | — | Tp-link Tl-wr902ac FirmwareTp-link Tl-wr802n FirmwareTp-link Tl-wr841n Firmware | 6/9/2023 | 17/6/2026 | Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: TL-WR802N firmware versions prior to 'TL-WR802N(JP)_V4_221008', TL-WR841N firmware versions prior to 'TL-WR841N(JP)_V14_230506', and TL-WR902AC firmware versions… | |
| Modificada | Alta (7.5) | 0.81% | — | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr941nd Firmware | 22/6/2023 | 17/6/2026 | TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3 and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/QoSRuleListRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | |
| Modificada | Alta (7.7) | 0.70% | — | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr941nd FirmwareTp-link Tl-wr743nd Firmware | 22/6/2023 | 17/6/2026 | TP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR841N V8 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlAccessTargetsRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | |
| Modificada | Alta (7.7) | 0.80% | — | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr941nd Firmware | 22/6/2023 | 17/6/2026 | An issue in the /userRpm/LocalManageControlRpm component of TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8/V10, and TL-WR941ND V5 allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | |
| Modificada | Alta (7.7) | 0.71% | — | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n FirmwareTp-link Tl-wr941nd Firmware | 22/6/2023 | 17/6/2026 | TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8, TL-WR941ND V5, and TL-WR740N V1/V2 were discovered to contain a buffer read out-of-bounds via the component /userRpm/VirtualServerRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | |
| Modificada | Alta (7.5) | 0.81% | — | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n FirmwareTp-link Tl-wr941nd Firmware | 22/6/2023 | 17/6/2026 | TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlTimeSchedRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | |
| Analizada | Alta (8.8) | 42% | ⚠ Explotación activa💥 PoC | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n Firmware | 7/6/2023 | 17/6/2026 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm . | |
| Modificada | Alta (8.1) | 0.90% | — | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n Firmware | 7/6/2023 | 17/6/2026 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/FixMapCfgRpm. | |
| Modificada | Alta (8.1) | 0.90% | — | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n Firmware | 7/6/2023 | 17/6/2026 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/WlanMacFilterRpm. | |
| Modificada | Alta (8.8) | 1.0% | — | Tp-link Tl-wr841n FirmwareTp-link Tl-wr841nd V7 Firmware | 20/12/2022 | 17/6/2026 | An issue in the firmware update process of TP-Link TL-WR841N / TL-WA841ND V7 3.13.9 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image. | |
| Modificada | Media (6.1) | 0.47% | — | Tp-link Tl-wr841n Firmware | 18/10/2022 | 17/6/2026 | TP-Link TL-WR841N 8.0 4.17.16 Build 120201 Rel.54750n is vulnerable to Cross Site Scripting (XSS). |