CVE-2018-25321

MEDIUM

TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attack...

Affects 2 products across 1 vendor.

BCS2.59
CVSS 3.14.3
CVSS v45.3
EPSS0.2%
Percentile8th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, no confidentiality impact, no availability impact.
CWE Weakness Definitions
CWE-352: Cross-Site Request Forgery (CSRF)

Web application does not verify that a request was intentionally sent by the authenticated user.

Related Attack Patterns (CAPEC)
CAPEC-462 Cross-Domain Search Timing
via CWE-352
CAPEC-467 Cross Site Identification
via CWE-352
CAPEC-62 Cross Site Request Forgery
via CWE-352
CAPEC-111 JSON Hijacking (aka JavaScript Hijacking)
via CWE-352

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The TP-Link TL-WR720N wireless router is vulnerable to a cross-site request forgery (CSRF) attack, enabling unauthorized administrative actions.

BSID: BS-2026-GLOBAL-128925-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2018-25321?
The TP-Link TL-WR720N wireless router is vulnerable to a cross-site request forgery (CSRF) attack, enabling unauthorized administrative actions.
What is the CVSS score for CVE-2018-25321?
CVE-2018-25321 has CVSS 4.3 (Medium). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N. EPSS: 0.2%.
Is CVE-2018-25321 actively exploited?
No confirmed active exploitation of CVE-2018-25321 as of 2026-05-30.
How do I remediate CVE-2018-25321?
Priority: MEDIUM.
What systems are affected by CVE-2018-25321?
CVE-2018-25321 affects: Tp-Link, Tp-Link.
Vulnerability Details
CVE IDCVE-2018-25321
BSIDBS-2026-GLOBAL-128925-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Published2026-05-17
Last Modified2026-05-18
ICS Relevance85%
Weakness (CWE)
SourceNVD
Official Description

TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers can modify port forwarding rules via VirtualServerRpm.htm or change WiFi security settings via WlanSecurityRpm.htm by tricking authenticated users into visiting attacker-controlled pages.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Attackers can exploit this vulnerability by crafting malicious web requests that trick authenticated users into visiting attacker-controlled pages, allowing them to modify port forwarding rules or change WiFi security settings.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Tp-Link Tl-Wr720N Firmware
Tp-Link Tl-Wr720N
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 69 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashea6ebe70d346b481316208e3aeb2c27ff8e9f78f1f24c6f40219c6463cb6a736bca7c80d5b4d17274074d1aab23db37449579c825c8816a90a66ef9c5deb1d71
Related CVEs affecting Tp-Link
CVE-2013-2578 10.0 cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC317... CVE-2013-2579 10.0 TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly... CVE-2024-25139 10.0 In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susc... CVE-2023-36355 9.9 TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipSt... CVE-2017-8220 9.9 TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 R...
View all Tp-Link CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →