vendor:
TL-WR840N
by:
purnendu ghosh
4.8
CVSS
MEDIUM
Cross Site Scripting (XSS)
79
CWE
Product Name: TL-WR840N
Affected Version From: 0.9.1 3.16 v0001.0 Build 171211 Rel.58800n
Affected Version To: TL-WR840N v5 00000005
Patch Exists: NO
Related CWE: CVE-2019-12195
CPE: o:tp-link:tl-wr840n_firmware:0.9.13.16v0001.0Build171211Rel.58800n
Platforms Tested: Windows 10
2019
TL-WR840N v5 00000005
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS payload, the network name changed automatically and the internet connection was disconnected. All the users become disconnected from the internet.
Mitigation:
To ensure your network to be safe from Renaming and internet disconnection.