TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks
- С сайта: Vulnerability(cybersecuritynews.com)
- Вернуться к списку новостей
TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks
Author: AbinayaTP-Link has issued a security advisory regarding a high-severity vulnerability affecting its TL-WR940N V6 wireless router. This vulnerability, tracked as CVE-2026-12935, could allow unauthenticated attackers to trigger a denial-of-service condition or achieve remote code execution on vulnerable devices under certain circumstances.
The issue lies within the router’s RTSP connection tracking (conntrack) feature. RTSP, or Real-Time Streaming Protocol, is commonly used to control multimedia streaming sessions. The vulnerable module processes RTSP-related network traffic within the router’s kernel, which is the core part of its operating system.
According to TP-Link, the vulnerability is caused by a stack-based buffer overflow. This occurs when specially crafted data exceeds the allocated memory.
An attacker can exploit this flaw by running a malicious RTSP server and convincing a device on the local network to connect to it. When a LAN client contacts the attacker-controlled RTSP server, it can return a malicious RTSP message.
TP-Link TL-WR940N Vulnerability
The vulnerable conntrack module may then process this data incorrectly, leading to memory corruption within the router’s kernel. This can crash the device, resulting in a denial-of-service attack, or potentially enable the execution of attacker-controlled code.
If an attacker successfully executes code remotely, it poses a serious security risk. They could alter network settings, intercept traffic, change DNS configurations, install persistent malicious software, or use the compromised router to target other devices on the local network.
The vulnerability has been assigned a CVSS v4.0 score of 8.7 out of 10, categorized as High. Its attack vector is network-based, with low attack complexity and no authentication required.
However, user interaction is necessary, as a LAN client must initiate a connection to the malicious RTSP server for exploitation to occur.
TP-Link confirmed that this vulnerability specifically affects the TL-WR940N hardware version V6. The company has released firmware updates to address the issue across supported regional versions.
The fixed releases include firmware version (EN)_V6_260528 for English devices, (US)_V6_260528 for US devices, and (JP)_V6_260527 for Japanese devices.
Users should verify the exact hardware version and regional firmware edition of their router before installing updates. Installing firmware intended for another regional model may lead to operational issues or device malfunction. Firmware updates should only be downloaded from TP-Link’s official support portal.
Until the router is updated, organizations and home users should limit unnecessary outbound RTSP connections from devices on their local networks.
Network administrators may also consider monitoring for unusual RTSP traffic, unexpected router reboots, or configuration changes that could indicate attempted exploitation.
TP-Link credited Ryo Shimada of Powder Keg Technologies, Inc. for responsibly disclosing this vulnerability. Prompt installation of the firmware remains the primary mitigation strategy for CVE-2026-12935.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now .
#Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news
Оригинальная версия на сайте:


