Impact
An authenticated stack‑based buffer overflow exists in the web management interface of TP‑Link Systems Inc. TL‑WR841N v14. A malicious user with valid credentials can send specially crafted HTTP requests that overflow a stack buffer, causing the embedded web server to crash and the device to reboot automatically. The flaw does not provide arbitrary code execution; the primary concern is the resulting denial‑of‑service for all users of the router at that time.
Affected Systems
The vulnerability applies to TP‑Link Systems Inc. TL‑WR841N running firmware v14 as detailed by the CNA. This consumer‑grade wireless router is commonly used in small office or home networks. No other firmware versions were listed as affected in the CNA data, but updating to a later release is recommended to avoid this issue.
Risk and Exploitability
The CVSS score of 6.8 places the flaw in the medium‑severity range. Exploitation requires authenticated access, which limits risk to accounts with administrative credentials. The attack vector is inferred to be via crafted HTTP requests to the web interface. EPSS data is not available, and the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation at this time, yet the crash and forced reboot still pose a tangible operational threat.
OpenCVE Enrichment