CVE-2026-12935

TP-Link · TL-WR940N v6

The TP-Link TL-WR940N v6 router contains a stack-based buffer overflow vulnerability in its RTSP connection tracking module.

Executive summary

A stack-based buffer overflow vulnerability in the TP-Link TL-WR940N v6 router allows unauthenticated remote attackers to potentially execute arbitrary code.

Vulnerability

This vulnerability exists in the RTSP connection tracking module, where improper handling of network traffic can trigger a stack-based buffer overflow. The attack is unauthenticated, though it requires user interaction to facilitate the exploitation process.

Business impact

Successful exploitation of this buffer overflow allows for the potential execution of arbitrary code with high privileges. This risk, reflected by a high CVSS score of 8.7, could result in complete device compromise, unauthorized network access, and the potential for the router to be recruited into botnets or used as a pivot point for further internal network attacks.

Remediation

Immediate Action: Update the firmware of the affected TL-WR940N v6 devices to the latest versions: (US)_V6_260528, (JP)_V6_260527, or (EU)_V6_260528, depending on the regional model.

Proactive Monitoring: Monitor device logs for unusual system crashes, unexpected reboots, or RTSP traffic patterns that deviate from established operational baselines.

Compensating Controls: Restrict access to the router management interface and disable unnecessary RTSP features if they are not required for specific network applications.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high severity and potential for total system compromise, administrators must prioritize the application of the vendor-supplied firmware updates. Ensure all regional variants are updated to the specified versions to eliminate the vulnerability and secure the network perimeter.