CVE-2019-12195
Last modified
CVE-2019-12195 is a vulnerability of currently unknown severity. TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. EPSS estimates a 1.79% chance of exploitation in the next 30 days.
Description
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS payload, the network name changed automatically and the internet connection was disconnected. All the users become disconnected from the internet.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tl-Wr840n Firmware | 0.9.1_3.16 |
References
- http://packetstormsecurity.com/files/153027/TP-LINK-TL-WR840N-Cross-Site-Scripting.htmlThird Party Advisory, VDB Entry
- https://www.tp-link.com/us/securityVendor Advisory
- http://packetstormsecurity.com/files/153027/TP-LINK-TL-WR840N-Cross-Site-Scripting.htmlThird Party Advisory, VDB Entry
- https://www.tp-link.com/us/securityVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-12195?
How severe is CVE-2019-12195?
How do I fix CVE-2019-12195?
Are you affected by CVE-2019-12195?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
