VendorsTP-Linktl-wr840n_firmwareall versions
Vulnerabilities

TP-Link TL-WR840N Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2021-41653
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
Published 2021-11-13 · Modified
10.0EPSS 0.760
CVE-2018-11714
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.
Published 2018-06-04 · Modified
10.0EPSS 0.681
CVE-2022-25060
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
Published 2022-02-25 · Modified
10.0EPSS 0.402
CVE-2020-36178
oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables). NOTE: oal_ipt_addBridgeIsolationRules is not the only function that calls util_execSystem.
Published 2021-01-06 · Modified
10.0EPSS 0.097
CVE-2022-25061
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
Published 2022-02-25 · Modified
9.8EPSS 0.587
CVE-2022-25064
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
Published 2022-02-25 · Modified
9.8EPSS 0.365
CVE-2021-46122
Tp-Link TL-WR840N (EU) v6.20 Firmware (0.9.1 4.17 v0001.0 Build 201124 Rel.64328n) is vulnerable to Buffer Overflow via the Password reset feature.
Published 2022-04-18 · Modified
9.0EPSS 0.016
CVE-2019-15060
The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payload in an IP address input field.
Published 2019-08-22 · Modified
8.8EPSS 0.040
CVE-2023-39471
TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.009
CVE-2026-3227
Authenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N
Published 2026-03-13 · Analyzed
8.5EPSS 0.019
CVE-2018-15172
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
Published 2018-08-15 · Modified
7.51 PoCEPSS 0.083
CVE-2022-25062
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published 2022-02-25 · Modified
7.5EPSS 0.035
CVE-2018-15840
TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets, as demonstrated by an "nmap -f" command.
Published 2019-03-29 · Modified
7.5EPSS 0.019
CVE-2022-26639
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter.
Published 2022-03-28 · Modified
7.2EPSS 0.013
CVE-2022-26640
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter.
Published 2022-03-28 · Modified
7.2EPSS 0.013
CVE-2022-26641
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.
Published 2022-03-28 · Modified
7.2EPSS 0.013
CVE-2022-26642
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter.
Published 2022-03-28 · Modified
7.2EPSS 0.013
CVE-2022-29402
TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allows attackers to connect to the UART port via a serial connection and execute commands as the root user without authentication.
Published 2022-05-25 · Modified
7.2EPSS 0.004
CVE-2014-9510
Cross-site request forgery (CSRF) vulnerability in the administration console in TP-Link TL-WR840N (V1) router with firmware before 3.13.27 build 141120 allows remote attackers to hijack the authentication of administrators for requests that change router settings via a configuration file import.
Published 2015-01-09 · Modified
6.8EPSS 0.010
CVE-2023-50224
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
6.5KEVEPSS 0.156
CVE-2021-29280
In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow
Published 2021-08-19 · Modified
6.4EPSS 0.008
CVE-2019-12195
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS payload, the network name changed automatically and the internet connection was disconnected. All the users become disconnected from the internet.
Published 2019-05-24 · Modified
4.81 PoCEPSS 0.018