CVE-2018-11714
Description
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.
In plain language
AI Worth attentionThis vulnerability in some older TP-Link TL-WR840N and TL-WR841N router firmware can let an attacker perform actions without logging in, if they can reach the router’s web interface. A typical small business should treat this as a real risk and plan to replace or isolate the affected router firmware, because no official fix is listed.
Improper session handling in TP-Link’s web CGI components (CWE-384) on TL-WR840N firmware and TL-WR841N firmware can be abused to bypass authentication by sending a crafted Referer header to /cgi/ endpoints, enabling unauthorized actions without prior login.
What to do now
- Check whether your TP-Link router model is TL-WR840N or TL-WR841N, and confirm the exact firmware version/build shown on the router’s admin page.
- If your firmware matches the affected versions (listed in the TL-WR840N/TL-WR841N entries for CVE-2018-11714), treat the router as vulnerable.
- Do not expose the router’s admin interface to the internet (remove/avoid port forwarding, UPnP, and any remote-administration features).
- Restrict access to the router admin interface to only trusted internal devices (or place the router behind a firewall that blocks access from untrusted networks).
- If no vendor patch exists for your specific firmware, plan to replace the router or upgrade to a firmware version known to not be in the affected set—coordinate with TP-Link support or your vendor—then recheck the firmware version after the upgrade.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-11714 and every CVE in our database. Create a free account — no credit card required.
Create Free Account