CVE-2025-9014
HIGHTP-Link TL-WR841N v14 < 250908 - Unauthenticated Denial of Service via Referer Header Check
Title source: llmDescription
A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input validation. A remote, unauthenticated attacker can exploit this flaw and cause Denial of Service on the web portal service.This issue affects TL-WR841N v14: before 250908.
References (4)
Core 4
Core References
Patch, Vendor Advisory vendor-advisory
https://www.tp-link.com/us/support/faq/4894/
Scores
CVSS v3
7.5
EPSS
0.0020
EPSS Percentile
42.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-476
CWE-20
Status
published
Products (1)
tp-link/tl-wr841n_firmware
< 250908
Published
Jan 15, 2026
Tracked Since
Feb 18, 2026