Skip to main content
QUIETLYTIC
Vulnerability

TP-Link TL-WR720N CSRF (CVE-2018-25321)

CVE-2018-25321 is a cross-site request forgery vulnerability in the TP-Link TL-WR720N wireless router, allowing unauthorized changes to port forwarding and WiFi security settings.

CVE-2018-25321
Threat Level
MEDIUM
CVSS
4.3
Status
Monitored
Confidence
High
Affected Products
TP-Link TL-WR720N

CVE-2018-25321 is a cross-site request forgery (CSRF) vulnerability in the TP-Link TL-WR720N, a low-cost consumer wireless router still deployed in many small offices and home networks.

What the vulnerability does

Per the vulnerability record, the router’s admin web interface fails to enforce CSRF protections on state-changing requests to at least two endpoints: VirtualServerRpm.htm, which handles port-forwarding rules, and WlanSecurityRpm.htm, which handles WiFi security settings. An attacker can craft a malicious web page or link that, when visited by a user who is currently authenticated to the router’s admin interface, silently submits requests on the victim’s behalf — modifying port forwarding rules or WiFi security settings without the user’s knowledge or consent.

This is a late-assigned CVE for an old vulnerability class (the CVE ID’s 2018 prefix reflects when the underlying flaw was originally reported, not the record’s ingestion date) — a reminder that formal CVE assignment can lag real disclosure by years, particularly for consumer/SOHO hardware.

Why this matters

Changing port-forwarding rules via CSRF lets an attacker expose an internal network service to the internet without the router owner’s awareness — a common pivot for turning a home/office network into a foothold. Changing WiFi security settings via the same mechanism could weaken or disable encryption, or change credentials. Because TP-Link TL-WR720N units are consumer/SOHO hardware often left on default configurations for years without firmware updates, and this class of router frequently reaches end-of-support without a vendor patch, this is a case where the practical mitigation is likely device replacement or network segmentation rather than a firmware fix — we have no evidence of a vendor patch for this specific issue in the sourced record.

What we don’t yet have

We don’t have a confirmed patched firmware version in the available record — TP-Link’s consumer router lines have inconsistent long-term patch support, and this model’s current support status isn’t established here. Treat this as an unresolved exposure unless a specific firmware release addressing it can be confirmed directly with TP-Link.

Confidence

The vulnerable endpoints and attack mechanics are specifically named, giving high confidence in the technical description itself; confidence in patch availability is separately unconfirmed, per the gap above.

Frequently Asked Questions

What is CVE-2018-25321? A cross-site request forgery vulnerability in the TP-Link TL-WR720N router’s admin interface, allowing an attacker to change port-forwarding rules or WiFi security settings without authorization.

Is there a fix for CVE-2018-25321? No confirmed patched firmware version is established in the available record — check directly with TP-Link for this model’s current support and firmware status.

Is CVE-2018-25321 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from the National Vulnerability Database (NVD)/CVE record, aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 NVD/CVE record

Related intelligence


Analyst tools