CVE-2020-14965: TP-Link Tl-WR740N Firmware
Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.
On TP-Link TL-WR740N v4 and TL-WR740ND v4 devices, an attacker with access to the admin panel can inject HTML code and change the HTML context of the target pages and stations in the access-control settings via targets_lists_name or hosts_lists_name. The vulnerability can also be exploited through a CSRF, requiring no authentication as an administrator.
Affected products
- TP-Link Tl-WR740N Firmware: affected versions not specified
- TP-Link Tl-WR740ND Firmware: affected versions not specified
Published 2020-06-23. Last modified 2026-06-17.