VendorsTP-Linktl-wr841n13.0
Vulnerabilities

TP-Link TL-WR841N router 13.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2018-11714
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.
Published 2018-06-04 · Modified
10.0EPSS 0.681
CVE-2018-12575
On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of authentication via an HTTP request.
Published 2018-07-02 · Modified
9.8EPSS 0.029
CVE-2018-12577
The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow authenticated blind Command Injection.
Published 2018-07-02 · Modified
8.8EPSS 0.027
CVE-2018-12574
CSRF exists for all actions in the web interface on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices.
Published 2018-07-02 · Modified
8.8EPSS 0.005
CVE-2026-5039
Predictable Default Cryptographic Key Used for DES Encryption in TP-Link TL-WL841N
Published 2026-04-23 · Analyzed
8.8EPSS 0.002
CVE-2018-12576
TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking.
Published 2018-07-02 · Modified
4.3EPSS 0.007