CVE-2026-76650
Pre-Authentication NULL Pointer Dereference in UPnP SOAP State Variable Query Processing in TP-Link TL-WR841N
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP state variable query requests. A specially crafted SOAP query may trigger unexpected termination or instability of the process hosting the UPnP service. Successful exploitation may result in a denial-of-service condition affecting UPnP discovery, state query, or related management functionality until the affected process is restarted or the device is rebooted.
| CWE | CWE-476 |
| Vendor | tp-link system inc. |
| Product | tl-wr841n v14 |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link system inc. tl-wr841n v14
Be the first to know when new unknown vulnerabilities affecting tp-link system inc. tl-wr841n v14 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
TP-Link System Inc. / TL-WR841N v14
0 < TL-WR841N(US)_V14_4.19 Build 260820 Rel.33478 0 < TL-WR841N(EU)_V14_4.19 Build 260821 Rel.56588
References
Credits
Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications