# TP-Link Systems vulnerabilities & exploitation

> As of 2026-10-05, Threadlinqs tracks 6 TP-Link Systems CVEs, 0 in the CISA Known Exploited Vulnerabilities catalog, linked to 0 tracked threat campaigns.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 6 TP-Link Systems CVEs published between 2026-08-15 and 2026-08-15. The busiest month was 2026-08 (6 new CVEs). None of them is listed in CISA KEV yet.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 6 of 6 tracked TP-Link Systems CVEs.

- [CVE-2025-30241](https://intel.threadlinqs.com/cve/CVE-2025-30241) — HIGH 8.6 · EPSS 0.5% · 2026-08-10
- [CVE-2025-30240](https://intel.threadlinqs.com/cve/CVE-2025-30240) — MEDIUM 5.1 · EPSS 0.2% · 2026-08-10
- [CVE-2025-30237](https://intel.threadlinqs.com/cve/CVE-2025-30237) — HIGH 8.7 · 2026-08-10
- [CVE-2025-30238](https://intel.threadlinqs.com/cve/CVE-2025-30238) — HIGH 8.6 · 2026-08-10
- [CVE-2025-30239](https://intel.threadlinqs.com/cve/CVE-2025-30239) — HIGH 8.5 · 2026-08-10
- [CVE-2026-15141](https://intel.threadlinqs.com/cve/CVE-2026-15141) — MEDIUM 5.3 · 2026-08-12

## Products affected

Threadlinqs normalises CPE and CNA product records across all 6 CVEs; 13 distinct TP-Link Systems products are affected. The most frequently affected:

- HB210 Pro(EU1)1.0 — 5 CVEs
- HB210 Pro(US2)1.0/1.6 — 5 CVEs
- HB210(EU1) 1.0 — 5 CVEs
- HB210(US2) 1.0 — 5 CVEs
- HB410( EU1) 1.0 — 5 CVEs
- HB610(CA) V2.0 — 5 CVEs
- HB610(EU1) — 5 CVEs
- HB610(US2) V2.6/2.0 — 5 CVEs
- HB710(EU1) 1.0 — 5 CVEs
- HB710(US2) V1.6/1.0 — 5 CVEs
- HB810(EU1) V2.0 — 5 CVEs
- HB810(US2) V1.0/1.6/2.0/2.6 — 5 CVEs
- TL-WR820N v2 — 1 CVE

## Threat activity

No tracked threat campaign references TP-Link Systems products or CVEs yet. Vulnerability records are still monitored for exploitation and linked as campaigns are ingested.

## How to prioritise TP-Link Systems patching

This order follows the data Threadlinqs holds for TP-Link Systems, not a generic severity checklist:

- No TP-Link Systems CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are [CVE-2025-30241](https://intel.threadlinqs.com/cve/CVE-2025-30241) (0.5%), [CVE-2025-30240](https://intel.threadlinqs.com/cve/CVE-2025-30240) (0.2%).
- 0 CVEs score Critical and 4 High on CVSS v3 (maximum 8.7, average 7.5); sequence these after KEV and high-EPSS items.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/tp-link-systems
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
