{"advisories":[{"id":"EUVD-2018-3733","source":"euvd","title":"An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of \"Referer: http://192.168.0.1/mainFrame.htm\" then no authentication is required for any action.","url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-3733"}],"cve":"CVE-2018-11714","epss":{"score":0.68053},"mitre":{"cpes":[],"created":"2018-06-04T14:00:00+00:00","description":"An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of \"Referer: http://192.168.0.1/mainFrame.htm\" then no authentication is required for any action.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2018/11xxx/CVE-2018-11714.json","references":["http://blog.securelayer7.net/time-to-disable-tp-link-home-wifi-router/","https://www.exploit-db.com/exploits/44781/"],"title":null,"updated":"2024-09-16T23:25:29.762000+00:00","vendors":[],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:h:tp-link:tl-wr840n:5.0:*:*:*:*:*:*:*","cpe:2.3:h:tp-link:tl-wr841n:13.0:*:*:*:*:*:*:*","cpe:2.3:o:tp-link:tl-wr840n_firmware:0.9.1_3.16:*:*:*:*:*:*:*","cpe:2.3:o:tp-link:tl-wr841n_firmware:0.9.1_4.16:*:*:*:*:*:*:*"],"created":"2018-06-04T14:29:00.500000+00:00","description":"An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of \"Referer: http://192.168.0.1/mainFrame.htm\" then no authentication is required for any action.","metrics":{"cvssV2_0":{"score":10.0,"vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C"},"cvssV3_0":{"score":9.8,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV3_1":{},"cvssV4_0":{}},"nvd_repo_path":"2018/CVE-2018-11714.json","references":["http://blog.securelayer7.net/time-to-disable-tp-link-home-wifi-router/","https://www.exploit-db.com/exploits/44781/"],"title":null,"updated":"2026-06-17T01:36:26.430000+00:00","vendors":["tp-link","tp-link$PRODUCT$tl-wr840n","tp-link$PRODUCT$tl-wr840n_firmware","tp-link$PRODUCT$tl-wr841n","tp-link$PRODUCT$tl-wr841n_firmware"],"weaknesses":["CWE-384"]},"opencve":{"changes":[],"cpes":{"data":["cpe:2.3:h:tp-link:tl-wr840n:5.0:*:*:*:*:*:*:*","cpe:2.3:h:tp-link:tl-wr841n:13.0:*:*:*:*:*:*:*","cpe:2.3:o:tp-link:tl-wr840n_firmware:0.9.1_3.16:*:*:*:*:*:*:*","cpe:2.3:o:tp-link:tl-wr841n_firmware:0.9.1_4.16:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2018-06-04T14:00:00+00:00","provider":"mitre"},"description":{"data":"An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of \"Referer: http://192.168.0.1/mainFrame.htm\" then no authentication is required for any action.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":10.0,"vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C"},"provider":"nvd"},"cvssV3_0":{"data":{"score":9.8,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"nvd"},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.68053},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["http://blog.securelayer7.net/time-to-disable-tp-link-home-wifi-router/","https://www.exploit-db.com/exploits/44781/"],"providers":["mitre","nvd"]},"title":{"data":null,"provider":null},"updated":{"data":"2024-11-21T03:43:52.910000+00:00","provider":"nvd"},"vendors":{"data":["tp-link","tp-link$PRODUCT$tl-wr840n","tp-link$PRODUCT$tl-wr840n_firmware","tp-link$PRODUCT$tl-wr841n","tp-link$PRODUCT$tl-wr841n_firmware"],"providers":["nvd"]},"weaknesses":{"data":["CWE-384"],"providers":["nvd"]}}}