🔐 CVE Alert

CVE-2026-76649

UNKNOWN 0.0

Pre-Authentication NULL Pointer Dereference in UPnP SOAP Action Request Processing in TP-Link TL-WR841N

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action requests. A specially crafted SOAP action request containing unexpected XML content may cause the UPnP daemon to terminate unexpectedly. Successful exploitation may result in a denial-of-service condition affecting UPnP functionality until the service is restarted or the device is rebooted.

CWE CWE-476
Vendor tp-link system inc.
Product tl-wr841n v14
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for tp-link system inc. tl-wr841n v14

Be the first to know when new unknown vulnerabilities affecting tp-link system inc. tl-wr841n v14 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

TP-Link System Inc. / TL-WR841N v14
0 < TL-WR841N(US)_V14_4.19 Build 260820 Rel.33478 0 < TL-WR841N(EU)_V14_4.19 Build 260821 Rel.56588

References

NVD ↗ CVE.org ↗ EPSS Data ↗
tp-link.com: https://www.tp-link.com/us/support/download/tl-wr841n/v14/#Firmware tp-link.com: https://www.tp-link.com/en/support/download/tl-wr841n/v14/#Firmware tp-link.com: https://www.tp-link.com/us/support/faq/5270/

Credits

Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications