TP-Link known exploited vulnerabilities
CISA lists 6 TP-Link CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2025-09-03), and 0 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2023-1389 (Archer AX21): EPSS 100.0%, added 2023-05-01
- CVE-2015-3035 (Multiple Archer Devices): EPSS 83.9%, added 2022-03-25
- CVE-2023-33538 (Multiple Routers): EPSS 41.6%, added 2025-06-16
- CVE-2025-9377 (Multiple Routers): EPSS 33.5%, added 2025-09-03
- CVE-2020-24363 (TL-WA855RE): EPSS 20.7%, added 2025-09-02
Most affected TP-Link products
Multiple Routers (2), TL-WR841N (1), TL-WA855RE (1), Archer AX21 (1), Multiple Archer Devices (1).
All TP-Link CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2025-9377 | Multiple Routers | Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection | 2025-09-03 | 2025-09-24 | 33.5% | – |
| CVE-2023-50224 | TL-WR841N | TL-WR841N Authentication Bypass by Spoofing | 2025-09-03 | 2025-09-24 | 15.6% | – |
| CVE-2020-24363 | TL-WA855RE | TP-link TL-WA855RE Missing Authentication for Critical Function | 2025-09-02 | 2025-09-23 | 20.7% | – |
| CVE-2023-33538 | Multiple Routers | Multiple Routers Command Injection | 2025-06-16 | 2025-07-07 | 41.6% | – |
| CVE-2023-1389 | Archer AX21 | Archer AX-21 Command Injection | 2023-05-01 | 2023-05-22 | 100.0% | – |
| CVE-2015-3035 | Multiple Archer Devices | Multiple Archer Devices Directory Traversal | 2022-03-25 | 2022-04-15 | 83.9% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors