Vendor

TP-Link

As of , 6 TP-Link vulnerabilities are on CISA's list of exploited vulnerabilities; 0 were added in 2026. Patch first: CVE-2015-3035.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2015-3035Directory TraversalTP-Link Multiple Archer DevicesPatch this weekMetasploit module; EPSS 0.840.84
2CVE-2023-1389Archer AX-21 Command InjectionTP-Link Archer AX21Patch this weekEPSS 0.990.99
3CVE-2025-9377Archer C7(EU) and TL-WR841N/ND(MS) OS Command InjectionTP-Link Multiple RoutersPatch soon0.34
4CVE-2023-33538Command InjectionTP-Link Multiple RoutersPatch soon0.42
5CVE-2020-24363Missing Authentication for Critical FunctionTP-Link TL-WA855REPatch soon0.21
6CVE-2023-50224Authentication Bypass by SpoofingTP-Link TL-WR841NPatch soon0.16

Products

  • Multiple Routers2 entries
  • Archer AX211 entry
  • Multiple Archer Devices1 entry
  • TL-WA855RE1 entry
  • TL-WR841N1 entry

Added each year

12342022: 1120222023: 1120232024: nonenone20242025: 4420252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20221
20231
2024none
20254
2026none

Used in ransomware