Новости компьютерной безопасности:

  Latest News

TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks

С сайта: Vulnerability(cybersecuritynews.com)

TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks

Author: Abinaya

TP-Link has issued a security advisory regarding a high-severity vulnerability affecting its TL-WR940N V6 wireless router. This vulnerability, tracked as CVE-2026-12935, could allow unauthenticated attackers to trigger a denial-of-service condition or achieve remote code execution on vulnerable devices under certain circumstances.

The issue lies within the router’s RTSP connection tracking (conntrack) feature. RTSP, or Real-Time Streaming Protocol, is commonly used to control multimedia streaming sessions. The vulnerable module processes RTSP-related network traffic within the router’s kernel, which is the core part of its operating system.

According to TP-Link, the vulnerability is caused by a stack-based buffer overflow. This occurs when specially crafted data exceeds the allocated memory.

An attacker can exploit this flaw by running a malicious RTSP server and convincing a device on the local network to connect to it. When a LAN client contacts the attacker-controlled RTSP server, it can return a malicious RTSP message.

TP-Link TL-WR940N Vulnerability
The vulnerable conntrack module may then process this data incorrectly, leading to memory corruption within the router’s kernel. This can crash the device, resulting in a denial-of-service attack, or potentially enable the execution of attacker-controlled code.

If an attacker successfully executes code remotely, it poses a serious security risk. They could alter network settings, intercept traffic, change DNS configurations, install persistent malicious software, or use the compromised router to target other devices on the local network.

The vulnerability has been assigned a CVSS v4.0 score of 8.7 out of 10, categorized as High. Its attack vector is network-based, with low attack complexity and no authentication required.

However, user interaction is necessary, as a LAN client must initiate a connection to the malicious RTSP server for exploitation to occur.

TP-Link confirmed that this vulnerability specifically affects the TL-WR940N hardware version V6. The company has released firmware updates to address the issue across supported regional versions.

The fixed releases include firmware version (EN)_V6_260528 for English devices, (US)_V6_260528 for US devices, and (JP)_V6_260527 for Japanese devices.

Users should verify the exact hardware version and regional firmware edition of their router before installing updates. Installing firmware intended for another regional model may lead to operational issues or device malfunction. Firmware updates should only be downloaded from TP-Link’s official support portal.

Until the router is updated, organizations and home users should limit unnecessary outbound RTSP connections from devices on their local networks.

Network administrators may also consider monitoring for unusual RTSP traffic, unexpected router reboots, or configuration changes that could indicate attempted exploitation.

TP-Link credited Ryo Shimada of Powder Keg Technologies, Inc. for responsibly disclosing this vulnerability. Prompt installation of the firmware remains the primary mitigation strategy for CVE-2026-12935.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC  Now .



#Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news

Оригинальная версия на сайте: TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks
Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.

Вернуться к списку новостей Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.


Новости проекта CSN:

✉ CSN.net4me.net

Обновление сайта csn.net4me.net

Обновление сайта csn.net4me.net 💻
cyber security news
  • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
  • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
  • Изменен механизм обработки и отображения опасных и критических уязвимостей.

Благодарим что вы с нами.


#CSN_обновление_сайта
https://csn.net4me.net/cyber_security_8301.html

Дополнительный материал

О проекте CSN

Проект CSN.net4me.net родился 16 Марта 2018 года.
Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

О проекте net4me

Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

Об источниках

Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

Информация

Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.