CyberMax
Home › Exploited CVEs

TP-Link known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 6 TP-Link CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2025-09-03), and 0 are known to be used in ransomware campaigns.

TP-Link CVEs added to CISA KEV per year
2022: 1202212023: 1202312025: 420254

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected TP-Link products

Multiple Routers (2), TL-WR841N (1), TL-WA855RE (1), Archer AX21 (1), Multiple Archer Devices (1).

All TP-Link CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2025-9377Multiple RoutersArcher C7(EU) and TL-WR841N/ND(MS) OS Command Injection2025-09-032025-09-2433.5%–
CVE-2023-50224TL-WR841NTL-WR841N Authentication Bypass by Spoofing2025-09-032025-09-2415.6%–
CVE-2020-24363TL-WA855RETP-link TL-WA855RE Missing Authentication for Critical Function2025-09-022025-09-2320.7%–
CVE-2023-33538Multiple RoutersMultiple Routers Command Injection2025-06-162025-07-0741.6%–
CVE-2023-1389Archer AX21Archer AX-21 Command Injection2023-05-012023-05-22100.0%–
CVE-2015-3035Multiple Archer DevicesMultiple Archer Devices Directory Traversal2022-03-252022-04-1583.9%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors