TP-Link Patches High-Severity Vulnerability in TL-WR940N V6 Router
TP-Link has released a security advisory addressing a high-severity vulnerability (CVE-2026-12935) in its TL-WR940N V6 wireless router. The flaw, rated 8.7 on the CVSS v4.0 scale, could allow unauthenticated attackers to trigger a denial-of-service (DoS) condition or execute remote code under specific conditions.
The vulnerability stems from a stack-based buffer overflow in the router’s RTSP (Real-Time Streaming Protocol) connection tracking module, which processes network traffic within the device’s kernel. Exploitation requires a local network client to connect to a malicious RTSP server, which then sends crafted data to corrupt memory in the router. Successful attacks could crash the device or enable arbitrary code execution, granting attackers control over network settings, traffic interception, DNS manipulation, or further compromise of connected devices.
The flaw affects only the TL-WR940N V6 hardware version, with regional firmware updates now available:
- English models: (EN)_V6_260528
- US models: (US)_V6_260528
- Japanese models: (JP)_V6_260527
Users are advised to verify their router’s hardware version and regional firmware before applying updates, as incorrect installations may cause malfunctions. TP-Link credited Ryo Shimada of Powder Keg Technologies for the responsible disclosure. Until patches are applied, mitigations include restricting outbound RTSP connections and monitoring for suspicious activity, such as unexpected reboots or configuration changes.
Source: https://cybersecuritynews.com/tp-link-rce-vulnerability/
TP-Link Systems Inc. cybersecurity rating report: https://www.rankiteo.com/company/tp-link
"id": "TP-1785774351",
"linkid": "tp-link",
"type": "Vulnerability",
"date": "5/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of TL-WR940N V6 wireless '
'router',
'industry': 'Technology (Networking Hardware)',
'name': 'TP-Link',
'type': 'Company'}],
'attack_vector': 'Network',
'customer_advisories': 'Users advised to verify hardware version and regional '
'firmware before applying updates, restrict outbound '
'RTSP connections, and monitor for suspicious activity',
'description': 'TP-Link has released a security advisory addressing a '
'high-severity vulnerability (CVE-2026-12935) in its TL-WR940N '
'V6 wireless router. The flaw, rated 8.7 on the CVSS v4.0 '
'scale, could allow unauthenticated attackers to trigger a '
'denial-of-service (DoS) condition or execute remote code '
'under specific conditions. The vulnerability stems from a '
'stack-based buffer overflow in the router’s RTSP (Real-Time '
'Streaming Protocol) connection tracking module, which '
'processes network traffic within the device’s kernel. '
'Exploitation requires a local network client to connect to a '
'malicious RTSP server, which then sends crafted data to '
'corrupt memory in the router. Successful attacks could crash '
'the device or enable arbitrary code execution, granting '
'attackers control over network settings, traffic '
'interception, DNS manipulation, or further compromise of '
'connected devices.',
'impact': {'downtime': 'Denial-of-Service (DoS) condition',
'operational_impact': 'Device crash, arbitrary code execution, '
'control over network settings, traffic '
'interception, DNS manipulation, further '
'compromise of connected devices',
'systems_affected': 'TL-WR940N V6 wireless router'},
'investigation_status': 'Vulnerability patched',
'post_incident_analysis': {'corrective_actions': 'Firmware updates released '
'to patch the vulnerability',
'root_causes': 'Stack-based buffer overflow in '
'RTSP connection tracking module'},
'recommendations': 'Restrict outbound RTSP connections until patches are '
'applied, monitor for suspicious activity, verify hardware '
'version and regional firmware before updating',
'references': [{'source': 'TP-Link Security Advisory'},
{'source': 'Ryo Shimada (Powder Keg Technologies)'}],
'response': {'communication_strategy': 'Security advisory published, users '
'advised to verify hardware version '
'and regional firmware before updating',
'containment_measures': 'Firmware updates released for affected '
'models',
'enhanced_monitoring': 'Monitor for suspicious activity (e.g., '
'unexpected reboots or configuration '
'changes)',
'remediation_measures': 'Apply regional firmware updates '
'(EN_V6_260528, US_V6_260528, '
'JP_V6_260527)'},
'title': 'TP-Link Patches High-Severity Vulnerability in TL-WR940N V6 Router',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'CVE-2026-12935 (Stack-based buffer overflow in '
'RTSP connection tracking module)'}