Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2021-46122

Disclosure Date: April 18, 2022 (last updated February 23, 2025)
Tp-Link TL-WR840N (EU) v6.20 Firmware (0.9.1 4.17 v0001.0 Build 201124 Rel.64328n) is vulnerable to Buffer Overflow via the Password reset feature.
Attacker Value
Unknown

CVE-2022-26642

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter.
Attacker Value
Unknown

CVE-2022-26641

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.
Attacker Value
Unknown

CVE-2022-26640

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter.
Attacker Value
Unknown

CVE-2022-26639

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter.
Attacker Value
Unknown

CVE-2020-36178

Disclosure Date: January 06, 2021 (last updated February 22, 2025)
oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables). NOTE: oal_ipt_addBridgeIsolationRules is not the only function that calls util_execSystem.
Attacker Value
Unknown

CVE-2019-12195

Disclosure Date: May 24, 2019 (last updated November 27, 2024)
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS payload, the network name changed automatically and the internet connection was disconnected. All the users become disconnected from the internet.
0
Attacker Value
Unknown

CVE-2018-15172

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
0
Attacker Value
Unknown

CVE-2018-11714

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.
0