CVE-2025-15606

A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitization, allows crafted requests to trigger a processing error that causes the httpd service to crash. Successful exploitation may allow the attacker to cause service interruption, resulting in a DoS condition.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:td-w8961nd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:td-w8961n:4:*:*:*:*:*:*:*

History

31 Mar 2026, 19:04

Type Values Removed Values Added
CPE cpe:2.3:h:tp-link:td-w8961n:4:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:td-w8961nd_firmware:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://www.tp-link.com/en/support/download/td-w8961n/v4/#Firmware - () https://www.tp-link.com/en/support/download/td-w8961n/v4/#Firmware - Product
References () https://www.tp-link.com/us/support/faq/5028/ - () https://www.tp-link.com/us/support/faq/5028/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Tp-link
Tp-link td-w8961n
Tp-link td-w8961nd Firmware
Summary
  • (es) Una vulnerabilidad de Denegación de Servicio (DoS) en el componente httpd de TP-Link TD-W8961N v4.0, debido a un saneamiento de entrada inadecuado, permite que solicitudes manipuladas desencadenen un error de procesamiento que provoca la caída del servicio httpd. La explotación exitosa puede permitir al atacante causar interrupción del servicio, resultando en una condición de DoS.

23 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 19:16

Updated : 2026-03-31 19:04


NVD link : CVE-2025-15606

Mitre link : CVE-2025-15606

CVE.ORG link : CVE-2025-15606


JSON object : View

Products Affected

tp-link

  • td-w8961n
  • td-w8961nd_firmware
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo