CVE-2026-76651
Deferred Deferred - Pending Action

Buffer Overflow in TP-Link TL-WR841N HTTP Service

Vulnerability report for CVE-2026-76651, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-31

Assigner: TPLink

Description

A buffer overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing multipart/form-data requests. Insufficient validation of an attacker-controlled boundary parameter may allow a remote unauthenticated attacker to submit a crafted request that corrupts memory by overwriting data beyond the bounds of an internal buffer. Successful exploitation may result in modification or corruption of process memory, potentially leading to undefined application behavior. Arbitrary code execution, information disclosure, and denial-of-service conditions have not been demonstrated.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-31
Generated
2026-09-18
AI Q&A
2026-08-29
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tp-link tl-wr841n 14

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a buffer overflow in the embedded HTTP service of TL-WR841N v14 routers. It occurs when processing multipart/form-data requests due to insufficient validation of an attacker-controlled boundary parameter. This allows a remote unauthenticated attacker to submit a crafted request that corrupts memory by overwriting data beyond an internal buffer's bounds.

Detection Guidance

This vulnerability involves a buffer overflow in the embedded HTTP service of TL-WR841N v14 when processing multipart/form-data requests. Detection may involve monitoring for unusual network traffic patterns or crashes in the device's HTTP service. No specific commands are provided in the context.

Impact Analysis

Exploitation may lead to modification or corruption of process memory, causing undefined application behavior. While arbitrary code execution, information disclosure, and denial-of-service conditions have not been demonstrated, memory corruption could still disrupt router functionality or lead to instability.

Compliance Impact

This vulnerability may lead to information disclosure or memory corruption, which could result in unauthorized access to sensitive data. This could potentially violate GDPR's data protection requirements or HIPAA's safeguards for protected health information if exploited.

Mitigation Strategies

Update the TL-WR841N v14 firmware to the latest version provided by TP-Link to address the buffer overflow vulnerability in the embedded HTTP service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76651. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart