TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTp Link Tl Wr841n
HWTp-Linkv14Tp Link Tl Wr841n Firmware
OSTp-Link0.9.1_4.18
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth Bypass
CWE
Related vulnerabilities
CVE-2018-12575CRITICAL9.8PL ✓same product
TP-Link TL-WR841N — obejście uwierzytelnienia w interfejsie webowym
CVE-2018-11714CRITICAL9.8PL ✓same product
TP-Link TL-WR840N/TL-WR841N — pominięcie uwierzytelnienia poprzez fałszywy nagłówek Referer
CVE-2025-9377HIGH8.6⚠ KEVsame product
The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link...
CVE-2023-33538HIGH8.8⚠ KEVsame product
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection v...
CVE-2015-3035HIGH7.5⚠ KEVsame product
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmwa...