Description
TP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR841N V8 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlAccessTargetsRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
References (1)
Core 1
Core References
Scores
CVSS v3
7.7
EPSS
0.0013
EPSS Percentile
32.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-120
Status
published
Products (4)
tp-link/tl-wr743nd_firmware
tp-link/tl-wr841n_firmware
tp-link/tl-wr940n_firmware
tp-link/tl-wr941nd_firmware
Published
Jun 22, 2023
Tracked Since
Feb 18, 2026