NULL Pointer Dereference Vulnerability in TL-WR841N by TP-Link
CVE-2026-76650
5.3MEDIUM
What is CVE-2026-76650?
A NULL pointer dereference vulnerability exists in the UPnP service of TP-Link's TL-WR841N v14 router. This security issue arises when handling SOAP state variable query requests, where a maliciously crafted query can lead to unexpected terminations or instability in the UPnP service process. Successful exploitation can result in a denial-of-service condition, disrupting UPnP discovery and related management functionalities until the affected process is restarted or the device is rebooted. It is essential for users to update their firmware to mitigate this vulnerability.
Affected Version(s)
TL-WR841N v14 0
TL-WR841N v14 0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications
