Executive brief
The TP-Link TL-WR940N v6 router, a device used to provide wireless internet in homes and small offices, contains a security flaw in how it handles streaming media connections. If a user on the network connects to a malicious video streaming server, an attacker can crash the router or potentially take full control of the device. This could allow an attacker to monitor internet traffic or use the router as a foothold to attack other devices on the local network.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in the RTSP (Real Time Streaming Protocol) connection tracking kernel module of the TP-Link TL-WR940N v6 router. The issue is triggered when a LAN-side client initiates a connection to a malicious external RTSP server; the server can then send a specially crafted RTSP message that causes improper memory handling within the router's kernel. An unauthenticated attacker can exploit this to achieve a denial-of-service (DoS) condition or remote code execution (RCE) with kernel privileges. TP-Link has released firmware updates (versions ending in 260527/260528 or later) to address this vulnerability.
Affected products
- TP-Link TL-WR940N v6 (US) Before (US)_V6_260528
- TP-Link TL-WR940N v6 (JP) Before (JP)_V6_260527
- TP-Link TL-WR940N v6 (EU) Before (EU)_V6_260528
Timeline
- 2026-07-29: advisory: NVD and TP-Link published the vulnerability details.
- 2026-05-28: patched: TP-Link released fixed firmware versions for US, JP, and EU regions.