CVE-2025-14739
Unknown
Unknown - Not Provided
Uninitialized Pointer Vulnerability in TP-Link WR940N/WR941ND Enables Root DoS and Code Execution
Publication date: 2025-12-18
Last updated on: 2026-04-29
Assigner: TPLink
Description
Description
Access of Uninitialized Pointer vulnerability in TP-Link WR940N and WR941ND allows local unauthenticated attackers the ability to execute DoS attack
and potentially arbitrary code execution
under the context of the ‘root’ user.This issue affects WR940N and WR941ND: ≤ WR940N v5 3.20.1 Build 200316,
≤
WR941ND v6 3.16.9 Build 151203.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tp-link | wr941nd | 6.0 |
| tp-link | wr940n | 5.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-824 | The product accesses or uses a pointer that has not been initialized. |