Cyber Posture

CVE-2025-25898

HighPublic PoC

Published: 13 February 2025

Published
13 February 2025
Modified
18 March 2025
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0014 33.4th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the pskSecret parameter at /userRpm/WlanSecurityRpm.htm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

Security Summary

CVE-2025-25898, published on 2025-02-13, is a buffer overflow vulnerability (CWE-787) affecting the TP-Link TL-WR841ND V11 router. The issue resides in the handling of the pskSecret parameter at the /userRpm/WlanSecurityRpm.htm endpoint, with a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Remote, unauthenticated attackers can exploit this vulnerability with low attack complexity and no user interaction by sending a crafted packet to the affected endpoint. Successful exploitation leads to a Denial of Service condition, disrupting the router's availability without impacting confidentiality or integrity.

A technical report detailing the vulnerability is available at https://github.com/2664521593/mycve/blob/main/TP-Link/BOF_in_TP-Link_TL-WR841ND-V11_1.pdf.

Details

CWE(s)
CWE-787

Affected Products

tp-link
tl-wr841nd firmware
all versions

References