VendorsTP-Linktl-wr802n_firmwareall versions
Vulnerabilities

TP-Link TL-WR802N Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2021-29302
TP-Link TL-WR802N(US), Archer_C50v5_US v4_200 <= 2020.06 contains a buffer overflow vulnerability in the httpd process in the body message. The attack vector is: The attacker can get shell of the router by sending a message through the network, which may lead to remote code execution.
Published 2021-04-12 · Modified
9.3EPSS 0.059
CVE-2021-4144
TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.
Published 2021-12-23 · Modified
8.8EPSS 0.019
CVE-2023-36489
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: TL-WR802N firmware versions prior to 'TL-WR802N(JP)_V4_221008', TL-WR841N firmware versions prior to 'TL-WR841N(JP)_V14_230506', and TL-WR902AC firmware versions prior to 'TL-WR902AC(JP)_V3_230506'.
Published 2023-09-06 · Modified
8.8EPSS 0.006
CVE-2026-3227
Authenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N
Published 2026-03-13 · Analyzed
8.5EPSS 0.018
CVE-2021-3275
Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers), Access Points, ADSL + DSL Gateways and Routers, which affects TD-W9977v1, TL-WA801NDv5, TL-WA801Nv6, TL-WA802Nv5, and Archer C3150v2 devices through the improper validation of the hostname. Some of the pages including dhcp.htm, networkMap.htm, dhcpClient.htm, qsEdit.htm, and qsReview.htm and use this vulnerable hostname function (setDefaultHostname()) without sanitization.
Published 2021-03-26 · Modified
6.1EPSS 0.018