MEDIUM · 4.3

CVE-2018-25321

TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers...

Vulnerability Description

TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers can modify port forwarding rules via VirtualServerRpm.htm or change WiFi security settings via WlanSecurityRpm.htm by tricking authenticated users into visiting attacker-controlled pages.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
Tp-LinkTl-Wr720N Firmware<= v1_130719
Tp-LinkTl-Wr720N-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-25321?

CVE-2018-25321 is a vulnerability with a CVSS score of 4.3 (MEDIUM). TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers...

How severe is CVE-2018-25321?

CVE-2018-25321 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-25321?

Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tl-Wr720N Firmware, Tp-Link Tl-Wr720N.