
An issue was discovered on TP-Link TL-WR840N. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.
Проблема обнаружена в TP-Link TL-WR840N. Она вызвана некорректной обработкой сессий в папке /cgi/ или файле /cgi. Если злоумышленник отправляет заголовок "Referer: http://192.168.0.1/mainFrame.htm", то для любого действия не требуется аутентификация.
статья [pt-br]: https://nous.sidneypepo.com/router2025.html