CVE-2026-76650
5.3
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Summary
A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP state variable query requests. A specially crafted SOAP query may trigger unexpected termination or instability of the process hosting the UPnP service.
Successful exploitation may result in a denial-of-service condition affecting UPnP discovery, state query, or related management functionality until the affected process is restarted or the device is rebooted.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link System Inc. | TL-WR841N v14 | 0 < TL-WR841N(US)_V14_4.19 Build 260820 Rel.33478 | affected |
| TP-Link System Inc. | TL-WR841N v14 | 0 < TL-WR841N(EU)_V14_4.19 Build 260821 Rel.56588 | affected |
Weaknesses
- CWE-476: CWE-476 NULL pointer dereference
References
- https://www.tp-link.com/us/support/download/tl-wr841n/v14/#Firmware
- https://www.tp-link.com/en/support/download/tl-wr841n/v14/#Firmware
- https://www.tp-link.com/us/support/faq/5270/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.