VendorsTP-Linktl-wr840nany version
Vulnerabilities

TP-Link TL-WR840N any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2022-25060
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
Published 2022-02-25 · Modified
10.0EPSS 0.402
CVE-2020-36178
oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables). NOTE: oal_ipt_addBridgeIsolationRules is not the only function that calls util_execSystem.
Published 2021-01-06 · Modified
10.0EPSS 0.097
CVE-2022-25061
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
Published 2022-02-25 · Modified
9.8EPSS 0.587
CVE-2022-25064
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
Published 2022-02-25 · Modified
9.8EPSS 0.365
CVE-2019-15060
The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payload in an IP address input field.
Published 2019-08-22 · Modified
8.8EPSS 0.040
CVE-2018-15172
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
Published 2018-08-15 · Modified
7.51 PoCEPSS 0.083
CVE-2022-25062
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published 2022-02-25 · Modified
7.5EPSS 0.035
CVE-2018-15840
TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets, as demonstrated by an "nmap -f" command.
Published 2019-03-29 · Modified
7.5EPSS 0.019
CVE-2021-29280
In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow
Published 2021-08-19 · Modified
6.4EPSS 0.008