← Vulnerability feed

Vulnerability record · CVE-2020-35575 · published 26 December 2020

CVE-2020-35575: Tp-link wa901nd firmware vulnerability

Tp Link · Wa901nd Firmware

A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.

9.8 CVSS 3.1 Critical EPSS 7.6% · top 5.6%
9.8CVSS 3.1 base score, v2 7.5
7.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
27Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

27 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-35575 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-9377TP-Link Archer C7 and TL-WR841N Parental Control OS Command InjectionAn OS command injection flaw (CWE-78) exists in the Parental Control page of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 routers, allowing an au…KEVEPSS 34%analysed7.5CVE-2015-3035TP-Link router directory traversal allows unauthenticated file readA path traversal flaw in the web interface of multiple TP-Link Archer and TL-WR/WDR router models lets a remote attacker read arbitrary files by plac…KEVEPSS 84%analysed6.5CVE-2023-50224TP-Link router httpd authentication bypass exposes stored credentialsThe httpd service on affected TP-Link router firmware contains an improper authentication flaw (CWE-290) that lets a network-adjacent attacker bypass…KEVEPSS 16%analysed9.8CVE-2022-4498Tp-link archer c5 firmware out-of-bounds write vulnerabilityIn TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication the httpd service can be sen…EPSS 1.8%8.0CVE-2023-39224Tp-link archer c7 firmware os command injection vulnerabilityArcher C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to…EPSS 0.40%7.5CVE-2022-4499Tp-link archer c5 firmware observable discrepancy vulnerabilityTP-Link routers, Archer C5 and WR710N-V1, using the latest software, the strcmp function used for checking credentials in httpd, is susceptible to a …EPSS 0.71%7.2CVE-2018-19537Tp-link archer c5 firmware unrestricted file upload vulnerabilityTP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuratio…EPSS 6.0%5.4CVE-2026-5363Tp-link archer c7 firmware inadequate encryption strength vulnerabilityInadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interfa…EPSS 0.11%

Source: NIST National Vulnerability Database (record CVE-2020-35575), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.