CVE-2021-41653
Published on: 11/13/2021 12:00:00 AM UTC
Last Modified on: 11/17/2021 02:41:00 PM UTC
Certain versions of Tl-wr840n from Tp-link contain the following vulnerability:
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
- CVE-2021-41653 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 10 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
TP-Link TL-WR840N V5(EU) - RCE - CVE-2021-41653 | k4m1ll0.com text/x-python |
![]() |
TP-Link - Security Advisory | TP-Link | www.tp-link.com text/html |
![]() |
WiFi Networking Equipment for Home & Business | TP-Link | tp-link.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Exploit/POC from Github
TP-Link TL-WR840N EU v5 Remote Code Execution
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Tp-link | Tl-wr840n | v5 | All | All | All |
Operating System | Tp-link | Tl-wr840n Firmware | All | All | All | All |
- cpe:2.3:h:tp-link:tl-wr840n:v5:*:*:*:*:*:*:*:
- cpe:2.3:o:tp-link:tl-wr840n_firmware:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
TP-Link TLWR840N V5 EU router - Remote Code execution k4m1ll0.com/cve-2021-41653… | 2021-11-12 17:28:06 |
![]() |
k4m1ll0.com/cve-2021-41653… | 2021-11-13 06:42:10 |
![]() |
TP-Link TL-WR840N EU v5 Remote Code Execution #CyberSecurity k4m1ll0.com/cve-2021-41653… | 2021-11-13 11:07:35 |
![]() |
TP-Link TL-WR840N V5(EU) - RCE - CVE-2021-41653 k4m1ll0.com/cve-2021-41653… | 2021-11-13 11:11:17 |
![]() |
TP-Link TL-WR840N V5(EU) - RCE - CVE-2021-41653 k4m1ll0.com/cve-2021-41653… | 2021-11-13 14:13:08 |
![]() |
CVE-2021-41653 : The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N EU _V5_171… twitter.com/i/web/status/1… | 2021-11-13 15:03:20 |
![]() |
Potentially Critical CVE Detected! CVE-2021-41653 Description: The PING function on the TP-Link TL-WR840N EU v5 rou… twitter.com/i/web/status/1… | 2021-11-13 16:00:08 |
![]() |
TP-Link TL-WR840N V5(EU) - RCE - CVE-2021-41653 | 2021-11-30 22:13:06 |