TP-Link TL-WR845N Hardcoded Root Password Vulnerability

Vulnerability

A vulnerability exists in the TP-Link TL-WR845N router, specifically in the versions TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219, due to a hardcoded password for the root account. This password can be extracted by analyzing the firmware, which is available on the manufacturer's public repository, or through a brute force attack via physical access to the router. The vulnerability allows unauthorized users to gain root privileges on the device.

Impact

Exploitation of this vulnerability provides unauthorized users with root access to the router, allowing full control over the device.

Reproduction

The vulnerability can be reproduced by physically accessing the TL-WR845N router and extracting the firmware from the SPI flash memory or downloading it from the TP-Link official website. Once the firmware is obtained, it can be analyzed using tools like Binwalk or FirmAudit to extract the files. The MD5 hashed root password is located in the 'squashfs-root/etc/passwd' and 'squashfs-root/etc/passwd.bak' files. After extracting the hashed password, it can be cracked to reveal the password as '1234'. The root username, 'admin', is in plain text. To validate the extracted credentials, the root password can be used to log into the root shell via UART port communication.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
4.8
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.