Executive brief
The TP-Link TL-WR841N wireless router contains a NULL pointer dereference vulnerability in its UPnP service, which allows network devices to discover and control other devices on the network. A specially crafted network request can cause the UPnP service to crash unexpectedly, temporarily disabling UPnP functionality until the service or device is manually restarted. This could disrupt home or office automation scenarios that rely on UPnP-enabled device discovery.
Technical details
A NULL pointer dereference vulnerability exists in the UPnP daemon on TP-Link TL-WR841N v14 when processing SOAP (Simple Object Access Protocol) action requests. An unauthenticated remote attacker on the network can send a specially crafted SOAP request with malformed XML content to trigger the vulnerability, causing the UPnP daemon process to dereference a NULL pointer and terminate abnormally. The attack requires network access to the router but no authentication. Successful exploitation results in denial-of-service (DoS) affecting UPnP functionality until the service is restarted or the device is rebooted. No patch information is currently available.
Affected products
- TP-Link TL-WR841N v14
Timeline
- 2026-08-28: disclosed