Access of Uninitialized Pointer Vulnerability in TP-Link Routers
CVE-2025-14739

6.8MEDIUM

Key Information:

Vendor
CVE Published:
18 December 2025

What is CVE-2025-14739?

The TP-Link WR940N and WR941ND routers are susceptible to an Access of Uninitialized Pointer vulnerability that allows local unauthenticated attackers to potentially execute a denial of service (DoS) attack and execute arbitrary code under the context of the 'root' user. This vulnerability affects specific firmware versions, making it crucial for users to ensure their devices are updated to mitigate this security risk.

Affected Version(s)

WR940N and WR941ND 0

WR940N and WR941ND 0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

VulnCheck
.