A NULL
pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing
SOAP state variable query requests. A specially crafted SOAP query may trigger
unexpected termination or instability of the process hosting the UPnP service.
Successful
exploitation may result in a denial-of-service condition affecting UPnP
discovery, state query, or related management functionality until the affected
process is restarted or the device is rebooted.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-28 22:16
Updated : 2026-09-01 20:50
NVD link : CVE-2026-76650
Mitre link : CVE-2026-76650
CVE.ORG link : CVE-2026-76650
JSON object : View
Products Affected
No product.
CWE
CWE-476
NULL Pointer Dereference
