Vulnerability record · CVE-2018-11714 · published 4 June 2018
CVE-2018-11714: TP-Link router CGI session handling bypass allows unauthenticated actions
Tp Link · Tl Wr840n Firmware
TP-Link TL-WR840N v5 and TL-WR841N v13 routers mishandle sessions on the /cgi/ path. Sending a Referer header of http://192.168.0.1/mainFrame.htm causes the device to skip authentication for any action. This lets anyone who can reach the router's web interface issue privileged requests without logging in.
Description
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and public exploit code available makes this a critical exposure for the affected routers.
What it is
TP-Link TL-WR840N v5 and TL-WR841N v13 routers mishandle sessions on the /cgi/ path. Sending a Referer header of http://192.168.0.1/mainFrame.htm causes the device to skip authentication for any action. This lets anyone who can reach the router's web interface issue privileged requests without logging in.
Impact
An attacker gains full unauthenticated control of the router's CGI actions, which can include changing configuration and other administrative operations, with high confidentiality, integrity and availability impact per the CVSS vector.
Attack surface
Reachable over the network via the router's HTTP web interface on the /cgi/ path; no authentication and no user interaction are required, only the ability to send a crafted Referer header.
Exploitation
Not listed in CISA KEV, but EPSS is 0.68053 (99.29th percentile) and both references are tagged Exploit, including an Exploit-DB entry, indicating public exploit code exists.
What to do
- Apply the latest TP-Link firmware for TL-WR840N v5 and TL-WR841N v13, or replace the devices if no fix is available.
- Disable remote management and restrict the web interface to trusted LAN clients only.
- Do not expose the router's HTTP management interface to the internet; place it behind a firewall or management VLAN.
- If the device cannot be patched, replace it with a supported model that enforces session authentication.
- Monitor router logs for unexpected CGI requests carrying a Referer of http://192.168.0.1/mainFrame.htm.
Detection
- Inspect HTTP request logs or packet captures for /cgi/ requests with Referer: http://192.168.0.1/mainFrame.htm.
- Alert on administrative CGI actions occurring without a prior successful login or session cookie.
- Baseline normal router management traffic and flag requests from unexpected source IPs to the web interface.
- Review router configuration changes for unauthorized modifications.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://blog.securelayer7.net/time-to-disable-tp-link-home-wifi-router/ | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/44781/ | ExploitThird Party AdvisoryVDB Entry |
| http://blog.securelayer7.net/time-to-disable-tp-link-home-wifi-router/ | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/44781/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-11714 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-11714), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.