Critical TP-Link Router Flaw Lets Unauthenticated Attackers Execute Code Remotely
ID: df2ee75b-a17f-588b-8d39-9cff0c0ac4c9
STIX ID: report--df2ee75b-a17f-588b-8d39-9cff0c0ac4c9
Feed Name: Cyber Press
A critical stack-based buffer overflow (CVE-2026-12935, CVSS v4.0 8.7) in the RTSP connection-tracking module of TP-Link TL-WR940N v6 allows unauthenticated attackers to achieve remote code execution or cause denial-of-service by inducing a LAN client to contact a malicious RTSP server. TP-Link has released firmware updates (EN_V6_260528, US_V6_260528, JP_V6_260527) — administrators should prioritize verifying and applying these patches to prevent device compromise and potential botnet recruitment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
