CVE-2023-23040: High severity tp-link wr940n firmware vulnerability
TP-Link router TL-WR940N V6 3.19.1 Build 180119 uses a deprecated MD5 algorithm to hash the admin password used for basic authentication.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23040?
The severity of CVE-2023-23040 is high with a CVSS score of 7.5.
How does CVE-2023-23040 affect TP-Link router TL-WR940N?
CVE-2023-23040 affects TP-Link router TL-WR940N V6 3.19.1 Build 180119 by using a deprecated MD5 algorithm to hash the admin password used for basic authentication.
Is TP-Link TL-WR940N vulnerable to CVE-2023-23040?
Yes, TP-Link TL-WR940N V6 3.19.1 Build 180119 is vulnerable to CVE-2023-23040.
How can I fix CVE-2023-23040?
To fix CVE-2023-23040, TP-Link TL-WR940N users should update their firmware to a version that no longer uses the deprecated MD5 algorithm for password hashing.
Where can I find more information about CVE-2023-23040?
You can find more information about CVE-2023-23040 on the following references: [Reference 1](https://midist0xf.medium.com/tl-wr940n-uses-weak-md5-hashing-algorithm-ae7b589860d2), [Reference 2](https://www.tp-link.com/en/support/download/tl-wr940n/#Firmware)