Description
The
TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking
module that can lead to a stack-based buffer overflow. The issue occurs when a
LAN client initiates a connection to a malicious RTSP server controlled by an
attacker. A specially crafted RTSP message may trigger improper memory handling
within the kernel module









Successful
exploitation of this vulnerability may result in a denial-of-service (DoS)
condition or allow remote code execution (RCE), potentially leading to full
compromise of the device. This vulnerability can be exploited by an
unauthenticated attacker under the device's default configuration.
Published: 2026-07-29
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The TL‑WR940N v6 router contains a stack‑based buffer overflow in its RTSP connection‑tracking kernel module. A malicious RTSP message, crafted by an attacker, can corrupt the stack when a LAN client initiates communication with an attacker‑controlled RTSP server. The overflow can lead to denial of service or allow the attacker to execute arbitrary code on the device, a classic example of CWE‑121.

Affected Systems

The affected device is the TP‑Link Systems Inc. TL‑WR940N v6 router running the default firmware configuration. Only this model and firmware version are listed as impacted in the CNA data.

Risk and Exploitability

The vulnerability has a CVSS score of 8.7 and an EPSS score of less than 1 %, indicating a high severity but low exploitation probability. It is not listed in the CISA KEV catalog. The attack requires an unauthenticated LAN client that can reach a malicious RTSP server controlled by the attacker. Once the crafted RTSP packet is processed by the kernel module, the attacker can trigger the buffer overflow, leading to a DoS or remote code execution, potentially compromising the entire device.

Generated by OpenCVE AI on August 3, 2026 at 13:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update for the TL‑WR940N v6 router from TP‑Link’s official download site
  • Disable the RTSP service or the connection‑tracking feature in the router’s administration interface if RTSP is not required
  • Configure the router with strong admin credentials, enable WPA3 on wireless, and keep the LAN network isolated from untrusted networks
  • Monitor router logs and network traffic for suspicious RTSP activity and block any unauthorized external addresses

Generated by OpenCVE AI on August 3, 2026 at 13:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link tl-wr940n V6
Vendors & Products Tp-link
Tp-link tl-wr940n V6

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow. The issue occurs when a LAN client initiates a connection to a malicious RTSP server controlled by an attacker. A specially crafted RTSP message may trigger improper memory handling within the kernel module Successful exploitation of this vulnerability may result in a denial-of-service (DoS) condition or allow remote code execution (RCE), potentially leading to full compromise of the device. This vulnerability can be exploited by an unauthenticated attacker under the device's default configuration.
Title Unauthenticated Remote Code Execution in TP-Link TL-WR940N RTSP Conntrack Feature
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Tl-wr940n V6
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-07-30T03:55:40.565Z

Reserved: 2026-06-22T18:48:17.939Z

Link: CVE-2026-12935

cve-icon Vulnrichment

Updated: 2026-07-29T18:45:44.850Z

cve-icon NVD

Status : Deferred

Published: 2026-07-29T19:16:44.113

Modified: 2026-07-30T14:12:18.697

Link: CVE-2026-12935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:15:05Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow