These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-84941 is an information disclosure vulnerability in Omada Controller's SAML Single Sign-On (SSO) functionality. An authenticated user with SAML configuration privileges can access sensitive information due to insufficient validation of user-supplied SAML metadata. This CVE was published on 2026-09-11T00:19:57.633Z and last modified on 2026-09-11T15:21:12.850Z.
CVE-2026-17176 is an OS command injection vulnerability in the TDDP module of Deco BE11000, allowing an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete device compromise, including unauthorized command execution, modification of device settings, and loss of confidentiality, integrity, and availabilit [truncated]
A missing authentication vulnerability in VPN configuration management was identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control. A remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials. This vulnerability requires immediate attention from defenders responsible for VPN configuration management systems, es [truncated]
CVE-2026-76652 is an authenticated directory traversal vulnerability in file upload functionality identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Successful exploitation could allow an authenticated remote attacker to write files to unintended locations, potentially overwriting or modifying files accessible to the affected service. This vulnerability has a medium severity level and defenders sh [truncated]
A stack-based out-of-bounds write vulnerability exists in the login request handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability by sending a specially crafted malformed HTTP request. Successful exploitation may cause the web service process to crash, resulting in a denial-of-service condition and tem [truncated]
CVE-2026-17251 is a NULL pointer dereference vulnerability in the HTTP request parsing functionality of TL-MR6400 v7. An unauthenticated remote attacker can trigger the vulnerability by sending a specially crafted HTTP request containing a malformed session cookie header. Successful exploitation may cause the HTTP service process to crash, resulting in a denial-of-service condition and temporary loss of m [truncated]
CVE-2026-9033 is a vulnerability in the captive portal service of certain TP-Link devices. An unauthenticated attacker with network access can terminate active captive portal sessions, forcing users to re-authenticate. This issue has a CVSS score of 6 and a severity of MEDIUM. The vulnerability affects several TP-Link models, including ER7212PC, ER605, ER7206, ER7406, ER707-M2, ER7412-M2, ER8411, ER706W, [truncated]
CVE-2026-19683 is a vulnerability in TP-Link Omada Gateways' Dynamic DNS (DDNS) functionality. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. [truncated]
CVE-2026-19586 is a pre-authentication OS command injection vulnerability in Omada gateways configured as OpenVPN Servers. Successful exploitation requires the OpenVPN Server feature to be enabled and reachable by the attacker. The vulnerability allows unauthenticated remote attackers to execute arbitrary commands, potentially leading to full device compromise.
CVE-2026-8619 is an unauthenticated denial-of-service vulnerability in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0, and Archer MR600 v2. A remote attacker on an adjacent network can send a specially crafted HTTP request to trigger a crash of the HTTP service process, making the web management interface and HTTP-dependent functionality temporarily unavailable.
CVE-2026-75616 is an OS command injection vulnerability in the Archer C20 v6 firmware's web management interface. An authenticated administrator could exploit this by executing arbitrary system commands, potentially leading to full device compromise. The vulnerability has a CVSS score of 8.5 and is considered HIGH severity. This vulnerability exists when processing certain WAN-related configuration operat [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T19:17:24.760Z and has not been modified since then. The CVE-2026-75619 vulnerability is a heap-based buffer overflow in the RTSP service of Tapo C100/C101 V5 devices. An authenticated attacker on the local network can exploit this by sending specially crafted RTSP frame data with oversized length [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T19:17:24.630Z and has not been modified since then. The vulnerability CVE-2026-75618 in Tp Link Tapo C100/C101 V5 devices is due to a null pointer dereference in the RTSP service. An attacker on the local network can send specially crafted requests to cause the service to dereference an invalid p [truncated]
The Tapo C120 v1 and C200 v5 devices contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management acti [truncated]
CVE-2026-15141 debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T23:17:19.703Z and has not been modified since then. The vulnerability affects TP-Link TL-WR820N devices with firmware versions up to 1.15.20. It allows adjacent attackers to obtain sensitive information due to insufficient validation logic in the web interface. The vulnerability has a CVSS score of 5.3 a [truncated]
CVE-2025-30241 debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T23:16:50.670Z and was last modified on 2026-09-29T11:10:00.150Z. The NVD entry is currently Awaiting Analysis. Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions. An au [truncated]
TP-Link Aginet devices are vulnerable to unauthorized read access due to improper validation of symbolic links on external USB storage devices. An attacker can create a crafted symbolic link to resolve and access sensitive files within the device filesystem. This vulnerability has a medium CVSS score of 5.1 and requires verification of affected scope and vendor remediation. Defenders should assess exposur [truncated]
TP-Link Aginet devices use hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data. An attacker with access to device storage can recover the keys and decrypt stored data, potentially gaining access to decrypted sensitive configuration data, including credentials and service-related information. This vulnerability allows attackers with device storage access to recover [truncated]
CVE-2025-30238 debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T23:16:49.900Z and has not been modified since then. This high-severity vulnerability in TP-Link Aginet devices allows authenticated low-privileged users to execute higher-privileged operations, potentially leading to administrative actions such as creating privileged accounts or modifying critical config [truncated]
TP-Link Aginet devices have a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. This allows an attacker to send specially crafted requests to bypass authentication and directly invoke privileged functionality without valid credentials. The issue arises from improper enforcement of access control mechanisms on sensitive operations. Successf [truncated]
An input validation vulnerability exists in the HTTP-WRITEOEM handler of the TP-Link Archer A6 v4 device due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic. This medium-severity vulnerability, with a CVSS score of 6.8, may cause the httpd process or device to crash, resulting in loss of access to the web interface and a denial-of-service cond [truncated]
The Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies. This may lead to a buffer overflow condition, causing the web service process to crash or stop responding, resulting in a denial-of-service condition. The vulnerability is due to insufficient input validation before memory copy operations, which can be exploited by [truncated]
A race condition exists in the cloud-based Omada device adoption process. An attacker may interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. This vulnerability allows attackers to obtain provisioning information intended for legitimate devices during the Omada device adoption process. Defenders should [truncated]
A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be able to recover session encryption keys and decrypt affected communications.
A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications.
A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices o [truncated]
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modi [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T23:17:26.767Z and has not been modified since then. The vulnerability exists in the VPN module of TP-Link AXE75 V1 routers, allowing an adjacent, authenticated attacker to execute arbitrary commands by importing a specially crafted VPN client configuration file. The issue arises from improper fil [truncated]
The CVE-2026-9770 vulnerability affects Tp Link Kasa EC71 v4 and EC70 v4 devices. The firmware for these devices contains a static cryptographic private key stored in a read-only filesystem, which is shared across devices. An attacker with access to the firmware image can extract this key. Successful exploitation may allow an unauthenticated attacker on the same network to compromise the confidentiality o [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-15T01:16:14.620Z and has not been modified since then. This vulnerability, identified in TP-Link Kasa EC70 v4 and EC71 v4, involves an information disclosure issue in the local discovery mechanism. It allows an attacker on the same local network to retrieve geolocation-related data without authentic [truncated]