CVE-2026-76650

NONE
CVSS v3
CVSS v2
0.18% EPSS (exploit probability)
CWE-476CWE

Description

A NULL
pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing
SOAP state variable query requests. A specially crafted SOAP query may trigger
unexpected termination or instability of the process hosting the UPnP service.





Successful
exploitation may result in a denial-of-service condition affecting UPnP
discovery, state query, or related management functionality until the affected
process is restarted or the device is rebooted.

Affected routers (1)

VendorModelMatched viaAffected versionsFixed inPatch Status
TP-Link TP-Link TL-WR841N Unpatched

External references