Security Advisory: Multiple Vulnerabilities in TP-Link TL-WR841N (CVE-2026-76649, CVE-2026-76650 & CVE-2026-76651)
Description of Vulnerabilities and Impacts:
Multiple vulnerabilities have been identified in TL-841N v14.
CVE-2026-76649: Pre-Authentication NULL Pointer Dereference in UPnP SOAP Action Request Processing
A NULL pointer dereference vulnerability exists in the UPnP service when processing SOAP action requests. A specially crafted SOAP action request containing unexpected XML content may cause the UPnP daemon to terminate unexpectedly.
Successful exploitation may result in a denial-of-service condition affecting UPnP functionality until the service is restarted or the device is rebooted.
CVE-2026-76650: Pre-Authentication NULL Pointer Dereference in UPnP SOAP State Variable Query Processing
A NULL pointer dereference vulnerability exists in the UPnP service when processing SOAP state variable query requests. A specially crafted SOAP query may trigger unexpected termination or instability of the process hosting the UPnP service.
Successful exploitation may result in a denial-of-service condition affecting UPnP discovery, state query, or related management functionality until the affected process is restarted or the device is rebooted.
CVE-2026-76649 and CVE-2026-76650 share the same CVSS scores:
CVSS v4.0 Score: 5.3/ Medium
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVE-2026-76651: Pre-Authentication Multipart Boundary Buffer Overflow in HTTP Service
A buffer overflow vulnerability exists in the embedded HTTP service when processing multipart/form-data requests. Insufficient validation of an attacker-controlled boundary parameter may allow a remote unauthenticated attacker to submit a crafted request that corrupts memory by overwriting data beyond the bounds of an internal buffer.
Successful exploitation may result in modification or corruption of process memory, potentially leading to undefined application behavior. Arbitrary code execution, information disclosure, and denial-of-service conditions have not been demonstrated.
CVSS v4.0 Score: 5.3/ Medium
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products/Versions and Fixes:
|
Product |
Fixed firmware |
|
TL-WR841N(US)_V14 |
4.19 Build 260820 Rel.33478 |
|
TL-WR841N(EU)_V14 |
4.19 Build 260821 Rel.56588 |
Recommendations:
We strongly recommend that users with affected devices take the following actions:
- Follow the instructions to update to the latest firmware version to fix the vulnerabilities:
US: Download for TL-WR841N | TP-Link
EN: Download for TL-WR841N | TP-Link
Disclaimer:
This advisory is provided for informational purposes only and is subject to change without notice. The information is provided “as is” without warranties of any kind. TP-Link recommends that customers promptly apply available firmware updates or implement documented workarounds as provided in this advisory. Devices/systems that are not updated or mitigated as described may remain vulnerable, and TP-Link disclaims any responsibility or liability for any damages or losses arising from a failure to implement such updates.
Looking For More
Is this faq useful?
Your feedback helps improve this site.
TP-Link Community
Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.