Executive brief
The TP-Link TL-WR720N wireless router, a device used to provide internet connectivity in homes and small offices, is vulnerable to an attack that can change its configuration without the owner's consent. By tricking a logged-in administrator into visiting a malicious website, an attacker can remotely modify critical settings such as Wi-Fi passwords and port forwarding rules. This could allow unauthorized access to the local network or disrupt internet services.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the TP-Link TL-WR720N router. The administrative pages, specifically VirtualServerRpm.htm and WlanSecurityRpm.htm, do not implement sufficient CSRF protections such as unique tokens. An attacker can exploit this by crafting malicious web requests and tricking an authenticated administrator into executing them via a browser. Successful exploitation allows the attacker to modify port forwarding rules, change Wi-Fi security protocols, or update the wireless password. The vulnerability affects all versions up to and including V1_130719.
Affected products
- TP-Link TL-WR720N All versions up to V1_130719
Timeline
- 2018-03-21: disclosed: Initial discovery and exploit development by Mans van Someren
- 2018-03-23: other: Exploit published on Exploit-DB
- 2026-05-17: advisory: CVE-2018-25321 published/updated in NVD via VulnCheck enrichment