CVE-2026-76649

A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action requests. A specially crafted SOAP action request containing unexpected XML content may cause the UPnP daemon to terminate unexpectedly. Successful exploitation may result in a denial-of-service condition affecting UPnP functionality until the service is restarted or the device is rebooted.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-28 22:16

Updated : 2026-09-01 20:50


NVD link : CVE-2026-76649

Mitre link : CVE-2026-76649

CVE.ORG link : CVE-2026-76649


JSON object : View

Products Affected

No product.

CWE
CWE-476

NULL Pointer Dereference