CVE-2018-25321 - CVE House
Back to Database
Status published Medium CVE-2018-25321

TP-Link TL-WR720N CSRF via Administrative Interfaces (firmware V1_130719)

Vulnerability Description

TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers can modify port forwarding rules via VirtualServerRpm.htm or change WiFi security settings via WlanSecurityRpm.htm by tricking authenticated users into visiting attacker-controlled pages.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25321

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Mans van Someren

Affected Vendor

Affected Software

TL-WR720NMbps Wireless N Router
Vulnerable Versions:
V1_130719

Timeline

Official Publish: May 17th, 2026
Last Modified: May 26th, 2026
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Weaknesses (CWE)