Tp-link
Tp-link Tl-wr840n Firmware: vulnerabilidades y CVE
Tp-link Tl-wr840n Firmware tiene 22 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 6 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses1
Críticas6
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-50224 | Media (6.5) | 16% | ⚠ Explotación activa | 3 may 2024 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-3227 | Alta (8.5) | 1.8% | — | 16 mar 2026 | A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import… |
| CVE-2023-50224 | Media (6.5) | 16% | ⚠ Explotación activa | 3 may 2024 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link… |
| CVE-2023-39471 | Alta (8.8) | 0.91% | — | 3 may 2024 | TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N routers.… |
| CVE-2022-29402 | Media (6.8) | 0.42% | — | 25 may 2022 | TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allows attackers to connect to the UART port via a serial connection and execute commands as the root… |
| CVE-2021-46122 | Alta (7.2) | 1.6% | — | 18 abr 2022 | Tp-Link TL-WR840N (EU) v6.20 Firmware (0.9.1 4.17 v0001.0 Build 201124 Rel.64328n) is vulnerable to Buffer Overflow via the Password reset feature. |
| CVE-2022-26642 | Alta (7.2) | 1.3% | — | 28 mar 2022 | TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter. |
| CVE-2022-26641 | Alta (7.2) | 1.3% | — | 28 mar 2022 | TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter. |
| CVE-2022-26640 | Alta (7.2) | 1.3% | — | 28 mar 2022 | TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter. |
| CVE-2022-26639 | Alta (7.2) | 1.3% | — | 28 mar 2022 | TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter. |
| CVE-2022-25064 | Crítica (9.8) | 36% | — | 25 feb 2022 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr. |
| CVE-2022-25062 | Alta (7.5) | 3.5% | — | 25 feb 2022 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. |
| CVE-2022-25061 | Crítica (9.8) | 59% | — | 25 feb 2022 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute. |
| CVE-2022-25060 | Crítica (9.8) | 40% | — | 25 feb 2022 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing. |
| CVE-2021-41653 | Crítica (9.8) | 76% | — | 13 nov 2021 | The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field. |
| CVE-2021-29280 | Media (6.4) | 0.75% | — | 19 ago 2021 | In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow |
| CVE-2020-36178 | Crítica (9.8) | 9.8% | — | 6 ene 2021 | oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the… |
| CVE-2019-15060 | Alta (8.8) | 4.0% | — | 22 ago 2019 | The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payload in an IP address input field. |
| CVE-2019-12195 | Media (4.8) | 1.8% | — | 24 may 2019 | TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS… |
| CVE-2018-15840 | Alta (7.5) | 1.9% | — | 29 mar 2019 | TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets, as demonstrated by an "nmap -f" command. |
| CVE-2018-15172 | Alta (7.5) | 8.3% | — | 15 ago 2018 | TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header. |
| CVE-2018-11714 | Crítica (9.8) | 68% | — | 4 jun 2018 | An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session… |
| CVE-2014-9510 | Media (6.8) | 0.98% | — | 9 ene 2015 | Cross-site request forgery (CSRF) vulnerability in the administration console in TP-Link TL-WR840N (V1) router with firmware before 3.13.27 build 141120 allows remote attackers to hijack the authentication of… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.