Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 4 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

TP-Link tl-wr840n_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

CWE-77CWE-78Feb 25, 2022
CVSS9.8v3.1EPSS36.2%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

TP-Link tl-wr840n_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

CWE-77CWE-78Feb 25, 2022
CVSS9.8v3.1EPSS39.9%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

TP-Link tl-wr840n_firmware Improper Control of Generation of Code ('Code Injection')

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.

CWE-94Nov 13, 20211 related artifact
CVSS9.8v3.1EPSS75.9%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

TP-Link tl-wr840n_firmware Session Fixation

An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.

CWE-384Jun 4, 2018
CVSS9.8v3.0EPSS35.4%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX