Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1191 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.29% | — | Tp-link Vx800v Firmware | 29/1/2026 | 17/6/2026 | Improper handling of exceptional conditions in VX800v v1.0 in SIP processing allows an attacker to flood the device with crafted INVITE messages, blocking all voice lines and causing a denial of service on incoming calls. | |
| Analizada | Media (6.9) | 0.27% | — | Tp-link Vx800v Firmware | 29/1/2026 | 17/6/2026 | Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files, resulting in high confidentiality impact and limited integrity risk. | |
| Analizada | Alta (7.7) | 0.17% | — | Tp-link Vx800v Firmware | 29/1/2026 | 17/6/2026 | A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force the weak AES key and decrypt intercepted traffic. Successful exploitation requires network proximity but no authentication, and may result in high impact to confidentiality, integrity, and… | |
| Analizada | Alta (7.3) | 0.48% | 💥 PoC | Tp-link Archer Re605x Firmware | 29/1/2026 | 17/6/2026 | The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker to gain root-level… | |
| Analizada | Alta (7.1) | 0.64% | — | Tp-link Tapo C220 FirmwareTp-link Tapo C520ws Firmware | 27/1/2026 | 17/6/2026 | By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying authentication or firmware integrity. An unauthenticated attacker can trigger a persistent denial of service, requiring a manual reboot or application initiated restart to… | |
| Modificada | Alta (7.1) | 0.59% | — | Tp-link Tapo C220 FirmwareTp-link Tapo C520ws Firmware | 27/1/2026 | 17/6/2026 | The HTTP parser of Tapo C210 v3, C220 v1 and C520WS v2 cameras improperly handles requests containing an excessively long URL path. An invalid‑URL error path continues into cleanup code that assumes allocated buffers exist, leading to a crash and service restart. An unauthenticated attacker can force repeated service… | |
| Modificada | Alta (7.1) | 0.73% | — | Tp-link Tapo C220 FirmwareTp-link Tapo C520ws Firmware | 27/1/2026 | 17/6/2026 | The Tapo C100 v5, C220 v1 and C520WS v2 cameras’ HTTP service does not safely handle POST requests containing an excessively large Content-Length header. The resulting failed memory allocation triggers a NULL pointer dereference, causing the main service process to crash. An unauthenticated attacker can repeatedly… | |
| Analizada | Media (5.1) | 0.28% | — | Tp-link Omada Controller | 26/1/2026 | 17/6/2026 | Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information. | |
| Analizada | Baja (2.1) | 0.32% | — | Tp-link Omada Controller | 26/1/2026 | 17/6/2026 | Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to weakened account security. | |
| Analizada | Alta (8.3) | 0.45% | — | Tp-link Omada Controller | 26/1/2026 | 17/6/2026 | An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account. | |
| Analizada | Alta (8.5) | 2.8% | — | Tp-link Archer Mr600 Firmware | 26/1/2026 | 17/6/2026 | Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to service disruption or full compromise. | |
| Analizada | Media (6) | 0.22% | — | Tp-link Omada ControllerTp-link Oc200 FirmwareTp-link Oc220 FirmwareTp-link Oc300 Firmware+52 | 22/1/2026 | 6/10/2026 | An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline… | |
| Analizada | Media (5.7) | 0.20% | — | Tp-link Omada ControllerTp-link Oc200 FirmwareTp-link Oc220 FirmwareTp-link Oc300 Firmware+1 | 22/1/2026 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker… | |
| Modificada | Alta (7.2) | 0.43% | 💥 PoC | Tp-link Archer Ax53 FirmwareTp-link Archer C20 Firmware | 21/1/2026 | 17/6/2026 | Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials. Attackers on the adjacent network can remotely trigger factory resets and… | |
| Aplazada | Alta (8.7) | 0.43% | — | Tp-link VigiAI | 16/1/2026 | 17/6/2026 | Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, compromising configuration… | |
| Analizada | Media (6.3) | 0.50% | — | Tp-link Tl-wr841n Firmware | 15/1/2026 | 17/6/2026 | A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input validation. A remote, unauthenticated attacker can exploit this flaw and cause Denial of Service on the web portal service.This issue affects TL-WR841N v14: before 250908. | |
| Analizada | Media (6.9) | 0.30% | — | Tp-link Archer Axe75 Firmware | 9/1/2026 | 17/6/2026 | Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary server file, leading to possible loss of critical system files and service interruption or degraded functionality.This issue affects Archer AXE75 v1.6: ≤ build 20250107. | |
| Analizada | Alta (7.1) | 0.23% | — | Tp-link Archer Be400 Firmware | 7/1/2026 | 17/6/2026 | A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows an adjacent attacker to cause a denial-of-service (DoS) by triggering a device reboot. This issue affects Archer BE400: xi 1.1.0 Build 20250710 rel.14914. | |
| Analizada | Media (6) | 0.30% | 💥 PoC | Tp-link Tl-wr820n Firmware | 29/12/2025 | 7/10/2026 | A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and decrypt SSH traffic. Exploitation may expose sensitive information and compromise confidentiality. | |
| Analizada | Alta (7.1) | 0.24% | — | Tp-link Tapo C200 Firmware | 20/12/2025 | 17/6/2026 | The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests to trigger excessive memory allocation, causing the device to crash and resulting in… | |
| Modificada | Alta (8.7) | 0.53% | — | Tp-link Tapo C200 Firmware | 20/12/2025 | 25/9/2026 | A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer. It allowed a crafted SOAP request with an oversized… | |
| Modificada | Alta (8.7) | 0.37% | — | Tp-link Tapo C200 Firmware | 20/12/2025 | 30/9/2026 | The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS). | |
| Aplazada | Media (6.8) | 0.21% | — | Tp-link Wr940nAITp-link Wr941ndAI | 18/12/2025 | 17/6/2026 | Access of Uninitialized Pointer vulnerability in TP-Link WR940N and WR941ND allows local unauthenticated attackers the ability to execute DoS attack and potentially arbitrary code execution under the context of the ‘root’ user.This issue affects WR940N and WR941ND: ≤ WR940N v5 3.20.1 Build 200316, ≤ WR941ND v6 3.16.9… | |
| Analizada | Media (5.7) | 0.41% | — | Tp-link Tl-wa850re Firmware | 18/12/2025 | 17/6/2026 | Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922. | |
| Analizada | Alta (7.1) | 0.94% | — | Tp-link Tl-wa850re Firmware | 18/12/2025 | 17/6/2026 | Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922. |