Impact
A NULL pointer dereference is triggered when the router processes a specially crafted SOAP action request in the UPnP service. The firmware bug causes the UPnP daemon to terminate unexpectedly, resulting in a denial‑of‑service condition that persists until the service is manually restarted or the device is rebooted.
Affected Systems
Only the TP‑Link TL‑WR841N series running firmware version 14 is affected. The vulnerability lies in the UPnP component of this router.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. EPSS data is not available, so precise exploit likelihood cannot be quantified; however based on the description it is inferred that the vulnerability is pre‑authentication and can be triggered by any network host that can send a malicious SOAP request, so careful observation of network traffic is prudent. The flaw is not listed in the CISA KEV catalog, meaning no publicly confirmed exploits are known at this time.
OpenCVE Enrichment