CVE-2025-29649

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Apr 16, 2025
Updated: Apr 24, 2025
CWE ID 89

Summary

CVE-2025-29649 is a newly identified SQL Injection vulnerability affecting the login dashboard of TP-Link TL-WR840N routers (version 1.0). An attacker can exploit this issue by injecting malicious SQL statements through the username and password fields, gaining unauthorized access to the system. However, it's important to note that the authenticity of this vulnerability is disputed due to the fact that it can only be reproduced on a supplier-provided emulator, where access controls are intentionally weakened for functional testing purposes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share