Vulnerability Description
On TP-Link TL-WR740N v4 and TL-WR740ND v4 devices, an attacker with access to the admin panel can inject HTML code and change the HTML context of the target pages and stations in the access-control settings via targets_lists_name or hosts_lists_name. The vulnerability can also be exploited through a CSRF, requiring no authentication as an administrator.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tl-Wr740N Firmware | - |
| Tp-Link | Tl-Wr740N | 4.0 |
| Tp-Link | Tl-Wr740Nd Firmware | - |
| Tp-Link | Tl-Wr740Nd | 4.0 |
Related Weaknesses (CWE)
References
- https://github.com/g-rubert/CVE-2020-14965Third Party Advisory
- https://github.com/g-rubert/CVE-2020-14965Third Party Advisory
FAQ
What is CVE-2020-14965?
CVE-2020-14965 is a vulnerability with a CVSS score of 4.8 (MEDIUM). On TP-Link TL-WR740N v4 and TL-WR740ND v4 devices, an attacker with access to the admin panel can inject HTML code and change the HTML context of the target pages and stations in the access-control se...
How severe is CVE-2020-14965?
CVE-2020-14965 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-14965?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tl-Wr740N Firmware, Tp-Link Tl-Wr740N, Tp-Link Tl-Wr740Nd Firmware, Tp-Link Tl-Wr740Nd.