peter bassill · operator
$ cve CVE-2019-12195 JSON

CVE-2019-12195 EXPLOIT

4.8
MEDIUM · CVSS 3.0 · EPSS 1.8% (pctl 77)

Patch early

A public exploit exists.

Description

TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS payload, the network name changed automatically and the internet connection was disconnected. All the users become disconnected from the internet.

Scoring

CVSS4.8 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS1.76% — more likely to be exploited than 77% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2019-05-24
Last modified2026-06-17

Affected (2)

VendorProduct
tp-linktl-wr840n
tp-linktl-wr840n firmware

Public exploits

SourceTitleDate
exploit-dbTP-LINK TL-WR840N v5 00000005 - Cross-Site Scripting2019-05-21

References

→ the Explorer  ·  watch your stack  ·  NVD