logo

TP-Link TL-WR940N Router Flaw Lets Unauthenticated Attackers Execute Code Remotely

ID: 3aa75f3e-f6e8-5d7e-a36f-02aefb7214b7

STIX ID: report--3aa75f3e-f6e8-5d7e-a36f-02aefb7214b7

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-08-03

Date Updated: 2026-08-04

Author: Divya

...
...

TP-Link disclosed a high-severity stack-based buffer overflow (CVE-2026-12935, CVSS 8.7) in the TL-WR940N v6 router's RTSP connection-tracking feature that can be triggered when a local client connects to an attacker-controlled RTSP server; successful exploitation may cause denial-of-service or remote code execution allowing full router compromise, and TP-Link has released firmware updates for v6 devices while recommending users update firmware and restrict untrusted streaming services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.