CVE-2025-25900

A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the username and password parameters at /userRpm/PPPoEv6CfgRpm.htm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tl-wr841nd_v11_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr841nd_v11:-:*:*:*:*:*:*:*

History

20 Jun 2025, 17:25

Type Values Removed Values Added
References () https://github.com/2664521593/mycve/blob/main/TP-Link/BOF_in_TP-Link_TL-WR841ND-V11_4.pdf - () https://github.com/2664521593/mycve/blob/main/TP-Link/BOF_in_TP-Link_TL-WR841ND-V11_4.pdf - Broken Link
CPE cpe:2.3:o:tp-link:tl-wr841nd_v11_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr841nd_v11:-:*:*:*:*:*:*:*
First Time Tp-link tl-wr841nd V11 Firmware
Tp-link
Tp-link tl-wr841nd V11

13 Mar 2025, 14:15

Type Values Removed Values Added
References () https://github.com/2664521593/mycve/blob/main/TP-Link/BOF_in_TP-Link_TL-WR841ND-V11_4.pdf - () https://github.com/2664521593/mycve/blob/main/TP-Link/BOF_in_TP-Link_TL-WR841ND-V11_4.pdf -
Summary
  • (es) Se descubrió una vulnerabilidad de desbordamiento de búfer en TP-Link TL-WR841ND V11 a través de los parámetros de nombre de usuario y contraseña en /userRpm/PPPoEv6CfgRpm.htm. Esta vulnerabilidad permite a los atacantes provocar una denegación de servicio (DoS) a través de un paquete manipulado.
CWE CWE-120

13 Feb 2025, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-13 16:16

Updated : 2025-06-20 17:25


NVD link : CVE-2025-25900

Mitre link : CVE-2025-25900

CVE.ORG link : CVE-2025-25900


JSON object : View

Products Affected

tp-link

  • tl-wr841nd_v11
  • tl-wr841nd_v11_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')