Cross-Site Request Forgery Vulnerability in TP-Link TL-WR841N
CVE-2018-12574
8.8HIGH
Summary
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the web interface of TP-Link TL-WR841N devices. This flaw allows unauthorized actions to be performed by an attacker if the user is authenticated in the web interface, potentially compromising the security of the device and the network. Users are advised to implement protective measures such as changing default credentials and ensuring firmware is up to date.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved