NULL Pointer Dereference Vulnerability in TL-WR841N Router from TP-Link
CVE-2026-76649

5.3MEDIUM

Key Information:

Vendor
CVE Published:
28 August 2026

What is CVE-2026-76649?

A NULL pointer dereference vulnerability exists in the UPnP service of TL-WR841N v14 routers related to the processing of SOAP action requests. An attacker can exploit this vulnerability by sending a specially crafted SOAP action request with unexpected XML content, leading to an unexpected termination of the UPnP daemon. This condition can disrupt UPnP functionality, requiring the service to be restarted or the device to be rebooted to restore normal operation.

Affected Version(s)

TL-WR841N v14 0

TL-WR841N v14 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications
.