这段漏洞描述信息翻译如下: TL-WR841N v14 的 UPnP 服务在处理 SOAP 状态变量查询请求时存在一个空指针解引用(NULL pointer dereference)漏洞。一个精心构造的 SOAP 查询可能导致托管 UPnP 服务进程意外终止或出现不稳定状况。 成功利用该漏洞可能导致拒绝服务(DoS)状态,影响 UPnP 发现、状态查询或相关管理功能,直到受影响进程重启或设备重新开机。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link System Inc. | TL-WR841N v14 | 0 ~ TL-WR841N(US)_V14_4.19 Build 260820 Rel.33478 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76651 | 5.3 MEDIUM | Pre-Authentication Multipart Boundary Buffer Overflow in HTTP Service in TP-Link TL-WR841N |
| CVE-2026-76649 | 5.3 MEDIUM | Pre-Authentication NULL Pointer Dereference in UPnP SOAP Action Request Processing in TP-L |
No comments yet