TP-Link vulnerabilities
7 CVEs tracked
TP-Link is prominently featured in our reports, particularly through its Omada ecosystem and Aginet devices. The main themes involve a chain of 15 newly discovered Zero Touch Provisioning (ZTP) vulnerabilities (CVEs unassigned) enabling full network takeover, alongside hardcoded credential (CVE-2026-12001) and OS command injection (CVE-2026-9044) flaws in various router models. The listed CVEs highlight critical issues such as authentication bypass (CVE-2025-30237), privilege escalation (CVE-2025-30238), and symlink manipulation (CVE-2025-30240). Defenders should immediately update Omada devices to the latest firmware, apply patches for CVE-2026-12001 and CVE-2026-9044, and restrict access to management interfaces through network segmentation.
Azərbaycanca: TP-Link, xüsusilə Omada ekosistemi və Aginet cihazları vasitəsilə hesabatlarımızda geniş yer alır. Əsas mövzular Zero Touch Provisioning (ZTP) mexanizmində aşkarlanan 15 yeni zəiflik (CVE hələ təyin edilməyib) zənciri ilə şəbəkənin tam ələ keçirilməsi riski və müxtəlif router modellərində aşkarlanan sərt kodlaşdırılmış etimadnamə (CVE-2026-12001) və əmr inyeksiyası (CVE-2026-9044) problemləridir. Sadalanan CVE-lər əsasən autentifikasiyadan yan keçmə (CVE-2025-30237), səlahiyyət yüksəltmə (CVE-2025-30238) və simvolik keçid manipulyasiyası (CVE-2025-30240) kimi kritik qüsurları əhatə edir. Müdafiəçilər dərhal Omada cihazlarını son firmware ilə yeniləməli, CVE-2026-12001 və CVE-2026-9044 üçün təminatları tətbiq etməli və şəbəkə seqmentasiyası vasitəsilə idarəetmə interfeyslərinə girişi məhdudlaşdırmalıdır.
This vendor's CVEs7
This hub is built from skopnix's own reporting on TP-Link: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.