Skip to content
COOEY

FAIL › dossier

tp-link

VENDOR

· dossier confidence 20%

TP-Link is a major wireless networking vendor with a significant security track record of critical RCE vulnerabilities in consumer routers that have been actively exploited by threat actors.

PROFILE
CategoryvendorWhat they doTP-Link is a global leader in wireless networking and smart home solutions, providing routers, mesh systems, and smart home devices. Websitehttps://www.tp-link.com ↗
SECURITY POSTURE

TP-Link has a history of critical remote code execution (RCE) vulnerabilities in consumer routers, including command injection and buffer overflow flaws in firmware components.

Notable failures
  • CVE-2021-42232: Command injection in tddp binary
  • CVE-2022-25061: Command injection via oal_setIp6DefaultRoute
  • CVE-2022-25060: Command injection via oal_startPing
  • CVE-2022-25064: RCE via oal_wan6_setIpAddr
  • CVE-2021-41653: RCE via crafted IP address payload
  • CVE-2023-34832: Buffer overflow in Archer AX10 firmware
Patterns: Repeated unpatched edge-device RCEs; Command injection in router firmware; Active exploitation by threat actors
FAILURE HISTORY · 13
DATEEVENTSEVSUMMARY
2025-09-03 CVE-2023-50224 high TP-Link TL-WR841N exposed due to unpatched spoofing vulnerability, actively exploited by threat actors.
2022-03-25 CVE-2015-3035 high TP-Link Archer routers suffer a directory traversal flaw allowing remote attackers to read arbitrary files, now actively exploited and cataloged by CISA.
2025-09-03 CVE-2025-9377 high TP-Link routers with CVE-2025-9377 actively exploited for command injection
2025-09-02 CVE-2020-24363 high TP-Link TL-WA855RE exposed to unauthenticated attacks via unpatched command injection flaw
2025-06-16 CVE-2023-33538 high TP-Link routers with CVE-2023-33538 actively exploited for command injection
2023-05-01 CVE-2023-1389 high TP-Link Archer AX-21 Command Injection Vulnerability
2026-03-20 CVE-2025-15608 critical This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions,
2022-08-23 CVE-2021-42232 critical TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on the
2022-02-25 CVE-2022-25064 critical TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
2022-02-25 CVE-2022-25060 critical TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
2022-02-25 CVE-2022-25061 critical TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
2021-11-13 CVE-2021-41653 critical The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
2023-06-16 CVE-2023-34832 critical TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
CISA and security vendors flagged this as critical RCE, indicating severe vendor liability and regulatory scrutiny.
cooey ↗severe-fallout-0.90
Critical RCE vulnerability disclosed
"The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field."
app.opencve.io ↗severe-fallout-0.50
Generic CVE listing, no vendor-specific sentiment
www.cvefind.com ↗severe-fallout-0.50
Generic CVE listing, no vendor-specific sentiment
SentinelOne ↗severe-fallout-0.50
Generic vulnerability database, no vendor-specific sentiment
cvefeed.io ↗severe-fallout-0.50
Generic CVE listing, no vendor-specific sentiment
www.claimdepot.com ↗severe-fallout-0.50
Generic class action site, no vendor-specific sentiment
CISA ↗severe-fallout-0.50
Generic ICS advisory page, no vendor-specific sentiment
Open questions: TP-Link's patch management process for enterprise-grade firmware · TP-Link's compliance with CMMC requirements for defense contractors
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:05:38.544449+00:00