CVE-2018-25321 is a cross-site request forgery (CSRF) vulnerability in the TP-Link TL-WR720N, a low-cost consumer wireless router still deployed in many small offices and home networks.
What the vulnerability does
Per the vulnerability record, the router’s admin web interface fails to enforce CSRF protections on state-changing requests to at least two endpoints: VirtualServerRpm.htm, which handles port-forwarding rules, and WlanSecurityRpm.htm, which handles WiFi security settings. An attacker can craft a malicious web page or link that, when visited by a user who is currently authenticated to the router’s admin interface, silently submits requests on the victim’s behalf — modifying port forwarding rules or WiFi security settings without the user’s knowledge or consent.
This is a late-assigned CVE for an old vulnerability class (the CVE ID’s 2018 prefix reflects when the underlying flaw was originally reported, not the record’s ingestion date) — a reminder that formal CVE assignment can lag real disclosure by years, particularly for consumer/SOHO hardware.
Why this matters
Changing port-forwarding rules via CSRF lets an attacker expose an internal network service to the internet without the router owner’s awareness — a common pivot for turning a home/office network into a foothold. Changing WiFi security settings via the same mechanism could weaken or disable encryption, or change credentials. Because TP-Link TL-WR720N units are consumer/SOHO hardware often left on default configurations for years without firmware updates, and this class of router frequently reaches end-of-support without a vendor patch, this is a case where the practical mitigation is likely device replacement or network segmentation rather than a firmware fix — we have no evidence of a vendor patch for this specific issue in the sourced record.
What we don’t yet have
We don’t have a confirmed patched firmware version in the available record — TP-Link’s consumer router lines have inconsistent long-term patch support, and this model’s current support status isn’t established here. Treat this as an unresolved exposure unless a specific firmware release addressing it can be confirmed directly with TP-Link.
Confidence
The vulnerable endpoints and attack mechanics are specifically named, giving high confidence in the technical description itself; confidence in patch availability is separately unconfirmed, per the gap above.
Frequently Asked Questions
What is CVE-2018-25321? A cross-site request forgery vulnerability in the TP-Link TL-WR720N router’s admin interface, allowing an attacker to change port-forwarding rules or WiFi security settings without authorization.
Is there a fix for CVE-2018-25321? No confirmed patched firmware version is established in the available record — check directly with TP-Link for this model’s current support and firmware status.
Is CVE-2018-25321 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.
Data sourced from the National Vulnerability Database (NVD)/CVE record, aggregated September 2026. See more vulnerability intelligence.