Cross-Site Request Forgery Vulnerability in TP-Link TL-WR841N
CVE-2018-12574

8.8HIGH

Key Information:

Vendor
Tp-link
Vendor
CVE Published:
2 July 2018

Summary

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the web interface of TP-Link TL-WR841N devices. This flaw allows unauthorized actions to be performed by an attacker if the user is authenticated in the web interface, potentially compromising the security of the device and the network. Users are advised to implement protective measures such as changing default credentials and ensuring firmware is up to date.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.