CVE-2020-36178: TP-Link Tl-WR840N Firmware

Critical severity, CVSS 9.8. EPSS: 9.8% chance of exploitation in the next 30 days.

oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables). NOTE: oal_ipt_addBridgeIsolationRules is not the only function that calls util_execSystem.

Affected products

  • TP-Link Tl-WR840N Firmware: version 6_eu_0.9.1_4.16 only

Published 2021-01-06. Last modified 2026-06-17.