Description
An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests to cause the embedded web server to overflow a stack buffer, resulting in a crash of the affected process.

Successful exploitation results in a denial-of-service condition, causing the device to crash and automatically reboot.
Published: 2026-06-29
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated stack‑based buffer overflow exists in the web management interface of TP‑Link Systems Inc. TL‑WR841N v14. A malicious user with valid credentials can send specially crafted HTTP requests that overflow a stack buffer, causing the embedded web server to crash and the device to reboot automatically. The flaw does not provide arbitrary code execution; the primary concern is the resulting denial‑of‑service for all users of the router at that time.

Affected Systems

The vulnerability applies to TP‑Link Systems Inc. TL‑WR841N running firmware v14 as detailed by the CNA. This consumer‑grade wireless router is commonly used in small office or home networks. No other firmware versions were listed as affected in the CNA data, but updating to a later release is recommended to avoid this issue.

Risk and Exploitability

The CVSS score of 6.8 places the flaw in the medium‑severity range. Exploitation requires authenticated access, which limits risk to accounts with administrative credentials. The attack vector is inferred to be via crafted HTTP requests to the web interface. EPSS data is not available, and the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation at this time, yet the crash and forced reboot still pose a tangible operational threat.

Generated by OpenCVE AI on June 29, 2026 at 18:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from TP‑Link to replace firmware v14
  • If an update cannot be applied immediately, disable the web management interface or restrict it to the local network only
  • Ensure that administrative accounts use strong, unique passwords and limit their use to trusted personnel

Generated by OpenCVE AI on June 29, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link tl-wr841n V14
Vendors & Products Tp-link
Tp-link tl-wr841n V14

Mon, 29 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 16:15:00 +0000

Type Values Removed Values Added
Description An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests to cause the embedded web server to overflow a stack buffer, resulting in a crash of the affected process. Successful exploitation results in a denial-of-service condition, causing the device to crash and automatically reboot.
Title Authenticated Stack-Based Buffer Overflow in TP-Link TL-WR841N Web Interface
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Tl-wr841n V14
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-06-29T16:18:26.269Z

Reserved: 2026-05-20T17:10:36.945Z

Link: CVE-2026-9105

cve-icon Vulnrichment

Updated: 2026-06-29T16:18:21.486Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T09:45:03Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow