
An issue was discovered on TP-Link TL-WR840N. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.
TP-Link TL-WR840N पर एक समस्या पाई गई है। यह समस्या /cgi/ फ़ोल्डर या /cgi फ़ाइल पर अनुचित सत्र प्रबंधन के कारण होती है। यदि कोई हमलावर "Referer: http://192.168.0.1/mainFrame.htm" का हेडर भेजता है, तो किसी भी कार्रवाई के लिए कोई प्रमाणीकरण आवश्यक नहीं है।
लेख [pt-br]: https://nous.sidneypepo.com/router2025.html