Impact
A buffer overflow exists in the embedded HTTP service of the TP‑Link TL‑WR841N v14 when parsing multipart/form-data requests. An attacker can control the boundary parameter, causing an internal buffer to be overwritten and corrupting memory. The vulnerability can lead to undefined application behavior, and while arbitrary code execution, information disclosure, and denial‑of‑service have not been demonstrated, the potential impact includes remote code execution and system compromise.
Affected Systems
The affected product is the TP‑Link TL‑WR841N router running firmware v14. No other versions are listed in the current data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Exploit probability is not reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is remote, unauthenticated, requiring the attacker to send a crafted HTTP request containing a malicious multipart boundary. Successful exploitation would require the vulnerable device to be reachable over the network and the HTTP service to be enabled. No definitive proof of exploitation has been reported, but memory corruption could provide elevated privileges if the overflow is triggered.
OpenCVE Enrichment