CVE-2026-76649
Pre-Authentication NULL Pointer Dereference in UPnP SOAP Action Request Processing in TP-Link TL-WR841N
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action requests. A specially crafted SOAP action request containing unexpected XML content may cause the UPnP daemon to terminate unexpectedly. Successful exploitation may result in a denial-of-service condition affecting UPnP functionality until the service is restarted or the device is rebooted.
| CWE | CWE-476 |
| Vendor | tp-link system inc. |
| Product | tl-wr841n v14 |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link system inc. tl-wr841n v14
Be the first to know when new unknown vulnerabilities affecting tp-link system inc. tl-wr841n v14 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
TP-Link System Inc. / TL-WR841N v14
0 < TL-WR841N(US)_V14_4.19 Build 260820 Rel.33478 0 < TL-WR841N(EU)_V14_4.19 Build 260821 Rel.56588
References
Credits
Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications