CVE-2018-18489: TP-Link WR840N Firmware

Medium severity, CVSS 4.9. EPSS: 1.7% chance of exploitation in the next 30 days.

The ping feature in the Diagnostic functionality on TP-LINK WR840N v2 Firmware 3.16.9 Build 150701 Rel.51516n devices allows remote attackers to cause a denial of service (HTTP service termination) by modifying the packet size to be higher than the UI limit of 1472.

Affected products

  • TP-Link WR840N Firmware: version 3.16.9 only

Published 2019-04-16. Last modified 2026-06-17.