FAIL › dossier
tp-link
VENDOR· dossier confidence 20%
TP-Link is a major wireless networking vendor with a significant security track record of critical RCE vulnerabilities in consumer routers that have been actively exploited by threat actors.
PROFILE
CategoryvendorWhat they doTP-Link is a global leader in wireless networking and smart home solutions, providing routers, mesh systems, and smart home devices.
Websitehttps://www.tp-link.com ↗
SECURITY POSTURE
TP-Link has a history of critical remote code execution (RCE) vulnerabilities in consumer routers, including command injection and buffer overflow flaws in firmware components.
Notable failures
- CVE-2021-42232: Command injection in tddp binary
- CVE-2022-25061: Command injection via oal_setIp6DefaultRoute
- CVE-2022-25060: Command injection via oal_startPing
- CVE-2022-25064: RCE via oal_wan6_setIpAddr
- CVE-2021-41653: RCE via crafted IP address payload
- CVE-2023-34832: Buffer overflow in Archer AX10 firmware
Patterns: Repeated unpatched edge-device RCEs; Command injection in router firmware; Active exploitation by threat actors
FAILURE HISTORY · 13
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-09-03 | CVE-2023-50224 | high | TP-Link TL-WR841N exposed due to unpatched spoofing vulnerability, actively exploited by threat actors. |
| 2022-03-25 | CVE-2015-3035 | high | TP-Link Archer routers suffer a directory traversal flaw allowing remote attackers to read arbitrary files, now actively exploited and cataloged by CISA. |
| 2025-09-03 | CVE-2025-9377 | high | TP-Link routers with CVE-2025-9377 actively exploited for command injection |
| 2025-09-02 | CVE-2020-24363 | high | TP-Link TL-WA855RE exposed to unauthenticated attacks via unpatched command injection flaw |
| 2025-06-16 | CVE-2023-33538 | high | TP-Link routers with CVE-2023-33538 actively exploited for command injection |
| 2023-05-01 | CVE-2023-1389 | high | TP-Link Archer AX-21 Command Injection Vulnerability |
| 2026-03-20 | CVE-2025-15608 | critical | This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, |
| 2022-08-23 | CVE-2021-42232 | critical | TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on the |
| 2022-02-25 | CVE-2022-25064 | critical | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr. |
| 2022-02-25 | CVE-2022-25060 | critical | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing. |
| 2022-02-25 | CVE-2022-25061 | critical | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute. |
| 2021-11-13 | CVE-2021-41653 | critical | The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field. |
| 2023-06-16 | CVE-2023-34832 | critical | TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
CISA and security vendors flagged this as critical RCE, indicating severe vendor liability and regulatory scrutiny.
Critical RCE vulnerability disclosed
"The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field."
Generic CVE listing, no vendor-specific sentiment
Generic CVE listing, no vendor-specific sentiment
Generic vulnerability database, no vendor-specific sentiment
Generic CVE listing, no vendor-specific sentiment
Generic class action site, no vendor-specific sentiment
Generic ICS advisory page, no vendor-specific sentiment
DOSSIER SOURCES
- 普联技术有限公司 - 企查查 · www.qcc.com
- Teleperformance (TLPFY) Company Profile, History, Products & Services · www.financecharts.com
- TP-Link Router Vulnerabilities Actively Exploited by Hackers, CISA ... · dailysecurityreview.com
- TP-Link Tapo for Android - Download the APK from Uptodown · tp-link-tapo.en.uptodown.com
- Guide : Quel répéteur wifi TP-Link choisir ? Juillet 2026 · www.lesnumeriques.com
- UpdateHub embedded Firmware Over-The-Air (FOTA) update · docs.zephyrproject.org
- OpManager Upgrade Packs - ManageEngine · www.manageengine.com
- How firmware and software updates work in Security Center SaaS - To ... · techdocs.genetec.com
Open questions: TP-Link's patch management process for enterprise-grade firmware · TP-Link's compliance with CMMC requirements for defense contractors
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:05:38.544449+00:00