CVE-2024-57040

Published Feb 26, 2025

Last updated 3 days ago

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2024-57040 is a vulnerability found in TP-Link TL-WR845N routers. Specifically, it affects version 4 firmware releases, including versions 200909 and 190219. The vulnerability stems from a hardcoded password for the root account being present within the router's firmware. This hardcoded password can be obtained through methods such as a brute-force attack. If successful, an attacker could gain unauthorized root-level access to the device, potentially leading to a compromise of the entire system and the ability to intercept network traffic.

Description
TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account which can be obtained by analyzing downloaded firmware or via a brute force attack through physical access to the router.
Source
cve@mitre.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-798

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2024-57040: Lỗ hổng nghiêm trọng (9.8/10) trong TP-Link TL-WR845N bị khai thác! Cập nhật bảo mật ngay. Xem: https://t.co/Pyhs898V6P #CyberSec #TPLink

    @CspWaf

    1 Apr 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ⚠️⚠️ CVE-2024-57040 (CVSS 9.8): TP-Link TL-WR845N Router Vulnerability Grants Hackers Easy Access 🎯15k+ Results are found on the https://t.co/pb16tGYaKe nearly year. 🔗FOFA Link: https://t.co/0ZJod7MnPD FOFA Query:app="TP_LINK-TL-WR845N" 🔖Refer:https://t.co/DXmHnWpb1z… http

    @fofabot

    17 Mar 2025

    738 Impressions

    1 Retweet

    8 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  3. 【admin:1234】TP-Link社のWi-FiルータTL-WR845Nに重大(Critical)な脆弱性。CVE-2024-57040はCVSSスコア9.8で、ハードコードされたrootシェル用の脆弱な認証情報。ファームウェアのsquashfs上のpasswdとpasswd.bakにMD5で保存されていた。 https://t.co/4YOqAjsXQT

    @__kokumoto

    17 Mar 2025

    5362 Impressions

    33 Retweets

    67 Likes

    12 Bookmarks

    1 Reply

    4 Quotes

  4. 🚨 Hackers Exploiting TP-Link Vulnerability to Gain Root Access Read more: https://t.co/cJiXe4AHtm The flaw, identified as CVE-2024-57040 and assigned a CVSS score of 9.8 (Critical), exposes hardcoded root shell credentials stored within the router's firmware files, creating…

    @The_Cyber_News

    17 Mar 2025

    401 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  5. CVE-2024-57040 (CVSS 9.8): TP-Link TL-WR845N Router Vulnerability Grants Hackers Easy Access Discover CVE-2024-57040, a critical vulnerability in TP-Link routers that exposes root credentials and risks full control. https://t.co/7NXt8TR8oa

    @the_yellow_fall

    17 Mar 2025

    576 Impressions

    5 Retweets

    7 Likes

    2 Bookmarks

    0 Replies

    0 Quotes