TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers can modify port forwarding rules via VirtualServerRpm.htm or change WiFi security settings via WlanSecurityRpm.htm by tricking authenticated users into visiting attacker-controlled pages.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 17 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link tl-wr720nmbps Wireless N Router |
|
| Vendors & Products |
Tp-link
Tp-link tl-wr720nmbps Wireless N Router |
Sun, 17 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers can modify port forwarding rules via VirtualServerRpm.htm or change WiFi security settings via WlanSecurityRpm.htm by tricking authenticated users into visiting attacker-controlled pages. | |
| Title | TP-Link TL-WR720N All Versions CSRF via Administrative Interfaces | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-17T12:11:28.176Z
Reserved: 2026-05-17T11:36:55.327Z
Link: CVE-2018-25321
No data.
Status : Received
Published: 2026-05-17T13:16:43.403
Modified: 2026-05-17T13:16:43.403
Link: CVE-2018-25321
No data.
OpenCVE Enrichment
Updated: 2026-05-17T17:00:14Z
Weaknesses