CVE-2026-3622

HIGH

Denial-of-Service Vulnerability in UPnP Component of TP Link's TL-WR841N

Title source: cna
STIX 2.1

Description

The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-bounds read, potentially causing a crash of the UPnP service. Successful exploitation can cause the UPnP service to crash, resulting in a Denial-of-Service condition.  This vulnerability affects TL-WR841N v14 < EN_0.9.1 4.19 Build 260303 Rel.42399n (V14_260303) and < US_0.9.1.4.19 Build 260312 Rel. 49108n (V14_0304).

Scores

CVSS v3 7.5
EPSS 0.0005
EPSS Percentile 15.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (2)
tp-link/tl-wr841n_firmware < 0.9.1_4.19
TP-Link Systems Inc./TL-WR841N v14 < 0.9.1 4.19
Published Mar 26, 2026
Tracked Since Mar 27, 2026