Tp-link
Tp-link Tl-wr940n Firmware: vulnerabilidades y CVE
Tp-link Tl-wr940n Firmware tiene 22 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses2
Críticas1
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-50224 | Media (6.5) | 16% | ⚠ Explotación activa | 3 may 2024 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link… |
| CVE-2023-33538 | Alta (8.8) | 42% | ⚠ Explotación activa | 7 jun 2023 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm . |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-11410 | Alta (8.5) | 2.8% | — | 17 jun 2026 | An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may… |
| CVE-2026-11409 | Alta (8.5) | 2.8% | — | 17 jun 2026 | An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this… |
| CVE-2025-6151 | Alta (8.2) | 5.0% | — | 17 jun 2025 | A vulnerability has been found in TP-Link TL-WR940N V4 and TL-WR841N V11. Affected by this issue is some unknown functionality of the file /userRpm/WanSlaacCfgRpm.htm, which may lead to buffer overflow. The attack may… |
| CVE-2024-54887 | Alta (8) | 5.7% | — | 9 ene 2025 | TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated… |
| CVE-2023-50224 | Media (6.5) | 16% | ⚠ Explotación activa | 3 may 2024 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link… |
| CVE-2023-36359 | Alta (7.5) | 0.81% | — | 22 jun 2023 | TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3 and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/QoSRuleListRpm. This vulnerability allows attackers to cause a Denial… |
| CVE-2023-36358 | Alta (7.7) | 0.70% | — | 22 jun 2023 | TP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR841N V8 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlAccessTargetsRpm. This vulnerability allows attackers to… |
| CVE-2023-36357 | Alta (7.7) | 0.80% | — | 22 jun 2023 | An issue in the /userRpm/LocalManageControlRpm component of TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8/V10, and TL-WR941ND V5 allows attackers to cause a Denial of Service (DoS) via a crafted GET request. |
| CVE-2023-36356 | Alta (7.7) | 0.71% | — | 22 jun 2023 | TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8, TL-WR941ND V5, and TL-WR740N V1/V2 were discovered to contain a buffer read out-of-bounds via the component /userRpm/VirtualServerRpm. This vulnerability allows attackers to… |
| CVE-2023-36355 | Crítica (9.9) | 32% | — | 22 jun 2023 | TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET… |
| CVE-2023-36354 | Alta (7.5) | 0.81% | — | 22 jun 2023 | TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlTimeSchedRpm. This vulnerability allows… |
| CVE-2023-33538 | Alta (8.8) | 42% | ⚠ Explotación activa | 7 jun 2023 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm . |
| CVE-2023-33537 | Alta (8.1) | 0.90% | — | 7 jun 2023 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/FixMapCfgRpm. |
| CVE-2023-33536 | Alta (8.1) | 0.90% | — | 7 jun 2023 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/WlanMacFilterRpm. |
| CVE-2022-43636 | Alta (8.8) | 0.91% | — | 29 mar 2023 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this vulnerability. The… |
| CVE-2022-43635 | Media (6.5) | 0.59% | — | 29 mar 2023 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this… |
| CVE-2022-24973 | Alta (8) | 0.72% | — | 28 mar 2023 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is required to exploit this… |
| CVE-2022-24972 | Media (6.5) | 0.58% | — | 28 mar 2023 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is not required to… |
| CVE-2022-0650 | Alta (8) | 0.72% | — | 28 mar 2023 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is required to exploit this… |
| CVE-2023-23040 | Alta (7.5) | 0.36% | — | 22 feb 2023 | TP-Link router TL-WR940N V6 3.19.1 Build 180119 uses a deprecated MD5 algorithm to hash the admin password used for basic authentication. |
| CVE-2022-24355 | Alta (8.8) | 2.1% | — | 18 feb 2022 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is not required to exploit this… |
| CVE-2019-6989 | Alta (8.8) | 11% | — | 6 jun 2019 | TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispose function. By sending specially crafted ICMP echo request packets, a remote authenticated attacker… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.