Executive brief
The TL-WR841N wireless router contains a buffer overflow vulnerability in its embedded web management interface when processing file upload requests with specially crafted boundaries. An attacker on the network can send a malicious request that corrupts the router's memory, potentially causing the device to malfunction or crash, disrupting network connectivity for all users relying on that router.
Technical details
A buffer overflow vulnerability exists in the HTTP service of TP-Link TL-WR841N v14 when processing multipart/form-data requests. The vulnerability stems from insufficient validation of the attacker-controlled boundary parameter, which allows an unauthenticated remote attacker to overwrite data beyond buffer bounds. The attack requires no authentication and is reachable over the network. Exploitation may result in memory corruption and undefined application behavior, though arbitrary code execution, information disclosure, and denial-of-service have not been demonstrated. No patch information is currently available.
Affected products
- TP-Link TL-WR841N v14
Timeline
- 2026-08-28: disclosed