TP-Link TL-WR940N Router Flaw Lets Unauthenticated Attackers Execute Code Remotely
ID: 3aa75f3e-f6e8-5d7e-a36f-02aefb7214b7
STIX ID: report--3aa75f3e-f6e8-5d7e-a36f-02aefb7214b7
Feed Name: GBHackers
Threat Score
TP-Link disclosed a high-severity stack-based buffer overflow (CVE-2026-12935, CVSS 8.7) in the TL-WR940N v6 router's RTSP connection-tracking feature that can be triggered when a local client connects to an attacker-controlled RTSP server; successful exploitation may cause denial-of-service or remote code execution allowing full router compromise, and TP-Link has released firmware updates for v6 devices while recommending users update firmware and restrict untrusted streaming services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
