Executive brief
TP-Link TL-WR841N v14 is a widely deployed home router that uses UPnP (Universal Plug and Play) for device discovery and management. A flaw in the UPnP service can be triggered by specially crafted network requests, causing the UPnP process to crash and temporarily disabling device discovery and network management features until the router is rebooted.
Technical details
A NULL pointer dereference vulnerability exists in the TL-WR841N v14 UPnP service when processing SOAP (Simple Object Access Protocol) state variable query requests. The vulnerability is triggered when a specially crafted SOAP query is sent to the device, causing an unhandled NULL pointer dereference in the UPnP process. An attacker on the local network (or remotely if UPnP is exposed) can send a malformed SOAP query to trigger unexpected process termination. Successful exploitation results in denial-of-service, disabling UPnP discovery and state queries until the affected service restarts or the device reboots. No patch information is currently available.
Affected products
- TP-Link TL-WR841N v14
Timeline
- 2026-08-28: disclosed