An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests to cause the embedded web server to overflow a stack buffer, resulting in a crash of the affected process.
Successful exploitation results in a denial-of-service condition, causing the device to crash and automatically reboot.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/en/support/download/tl-wr841n/v14/#Firmware | Product |
| https://www.tp-link.com/us/support/download/tl-wr841n/v14/#Firmware | Product |
| https://www.tp-link.com/us/support/faq/5152/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
01 Jul 2026, 19:57
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.tp-link.com/en/support/download/tl-wr841n/v14/#Firmware - Product | |
| References | () https://www.tp-link.com/us/support/download/tl-wr841n/v14/#Firmware - Product | |
| References | () https://www.tp-link.com/us/support/faq/5152/ - Vendor Advisory | |
| CWE | CWE-787 | |
| First Time |
Tp-link
Tp-link tl-wr841n Tp-link tl-wr841n Firmware |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CPE | cpe:2.3:h:tp-link:tl-wr841n:14:*:*:*:*:*:*:* cpe:2.3:o:tp-link:tl-wr841n_firmware:*:*:*:*:*:*:*:* |
29 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-29 16:16
Updated : 2026-07-01 19:57
NVD link : CVE-2026-9105
Mitre link : CVE-2026-9105
CVE.ORG link : CVE-2026-9105
JSON object : View
Products Affected
tp-link
- tl-wr841n
- tl-wr841n_firmware
