CVE-2026-102294
- EPSS 0.92%
- Veröffentlicht 01.10.2026 17:30:19
- Zuletzt bearbeitet 02.10.2026 04:18:03
TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary ...
CVE-2026-76651
- EPSS 0.3%
- Veröffentlicht 28.08.2026 20:19:09
- Zuletzt bearbeitet 01.09.2026 20:50:58
A buffer overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing multipart/form-data requests. Insufficient validation of an attacker-controlled boundary parameter may allow a remote unauthenticated attacker to sub...
CVE-2026-76650
- EPSS 0.18%
- Veröffentlicht 28.08.2026 20:19:03
- Zuletzt bearbeitet 01.09.2026 20:50:58
A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP state variable query requests. A specially crafted SOAP query may trigger unexpected termination or instability of the process hosting the UPnP ...
CVE-2026-76649
- EPSS 0.18%
- Veröffentlicht 28.08.2026 20:18:57
- Zuletzt bearbeitet 01.09.2026 20:50:58
A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action requests. A specially crafted SOAP action request containing unexpected XML content may cause the UPnP daemon to terminate unexpectedly. ...
CVE-2026-9105
- EPSS 0.81%
- Veröffentlicht 29.06.2026 16:16:44
- Zuletzt bearbeitet 01.07.2026 19:57:52
An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests to cause the embedded web server to overflow a stack buffer, r...
CVE-2026-5039
- EPSS 0.13%
- Veröffentlicht 23.04.2026 16:10:13
- Zuletzt bearbeitet 05.05.2026 14:11:58
TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default web management credentials, making the key predictable if device is left in default configuration. A network-adjacent attacker ca...
CVE-2026-3622
- EPSS 0.36%
- Veröffentlicht 26.03.2026 20:34:36
- Zuletzt bearbeitet 31.03.2026 19:09:04
The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-bounds read, potentially causing a crash of the UPnP service. Successful exploitation can cause the UPnP service to crash, resultin...
CVE-2025-9014
- EPSS 0.45%
- Veröffentlicht 15.01.2026 17:36:06
- Zuletzt bearbeitet 30.01.2026 20:42:05
A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input validation. A remote, unauthenticated attacker can exploit this flaw and cause Denial of Service on the ...
CVE-2025-53715
- EPSS 0.31%
- Veröffentlicht 29.07.2025 17:58:32
- Zuletzt bearbeitet 01.08.2025 18:42:34
A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/Wan6to4TunnelCfgRpm.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and re...
CVE-2025-53714
- EPSS 0.31%
- Veröffentlicht 29.07.2025 17:58:21
- Zuletzt bearbeitet 01.08.2025 18:42:39
A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WzdWlanSiteSurveyRpm_AP.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service an...