CVE-2020-14965

On TP-Link TL-WR740N v4 and TL-WR740ND v4 devices, an attacker with access to the admin panel can inject HTML code and change the HTML context of the target pages and stations in the access-control settings via targets_lists_name or hosts_lists_name. The vulnerability can also be exploited through a CSRF, requiring no authentication as an administrator.
References
Link Resource
https://github.com/g-rubert/CVE-2020-14965 Third Party Advisory
Configurations

Configuration 1


Information

Published : 2020-06-23 02:15

Updated : 2021-07-21 11:39


NVD link : CVE-2020-14965

Mitre link : CVE-2020-14965

Products Affected
No products.
CWE