CVE-2026-76649
Deferred Deferred - Pending Action

NULL Pointer Dereference in TP-Link TL-WR841N UPnP Service

Vulnerability report for CVE-2026-76649, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-31

Assigner: TPLink

Description

A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action requests. A specially crafted SOAP action request containing unexpected XML content may cause the UPnP daemon to terminate unexpectedly. Successful exploitation may result in a denial-of-service condition affecting UPnP functionality until the service is restarted or the device is rebooted.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-31
Generated
2026-09-18
AI Q&A
2026-08-29
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tp-link tl-wr841n 14

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a NULL pointer dereference in the TL-WR841N v14 router's UPnP service. It occurs when processing SOAP action requests with unexpected XML content, causing the UPnP daemon to crash. This leads to a denial-of-service condition affecting UPnP functionality until the service is restarted or the device is rebooted.

Detection Guidance

This vulnerability can be detected by monitoring the UPnP service on TL-WR841N v14 devices for unexpected crashes or termination. Check if the UPnP daemon stops responding or if the device becomes unresponsive after processing SOAP requests. Use network scanning tools to identify affected devices and verify their firmware versions.

Impact Analysis

Exploitation may disrupt UPnP services on your TL-WR841N v14 device, causing temporary loss of network functionality like device discovery and automatic port forwarding. The impact is limited to UPnP features and requires a reboot or service restart to resolve.

Compliance Impact

This vulnerability causes a denial-of-service condition in the UPnP service, which may disrupt network functionality. However, the provided context does not specify direct impacts on compliance with standards like GDPR or HIPAA.

Mitigation Strategies

Disable the UPnP service on affected devices if not required. Update the device firmware to the latest version if a patch is available. Restrict access to the UPnP port (typically UDP 1900) using firewall rules. Monitor the device for unusual activity or crashes and restart the UPnP service if it becomes unresponsive.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76649. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart