CVE-2026-12935
TP-Link · TL-WR940N v6
The TP-Link TL-WR940N v6 router contains a stack-based buffer overflow vulnerability in its RTSP connection tracking module.
Executive summary
A stack-based buffer overflow vulnerability in the TP-Link TL-WR940N v6 router allows unauthenticated remote attackers to potentially execute arbitrary code.
Vulnerability
This vulnerability exists in the RTSP connection tracking module, where improper handling of network traffic can trigger a stack-based buffer overflow. The attack is unauthenticated, though it requires user interaction to facilitate the exploitation process.
Business impact
Successful exploitation of this buffer overflow allows for the potential execution of arbitrary code with high privileges. This risk, reflected by a high CVSS score of 8.7, could result in complete device compromise, unauthorized network access, and the potential for the router to be recruited into botnets or used as a pivot point for further internal network attacks.
Remediation
Immediate Action: Update the firmware of the affected TL-WR940N v6 devices to the latest versions: (US)_V6_260528, (JP)_V6_260527, or (EU)_V6_260528, depending on the regional model.
Proactive Monitoring: Monitor device logs for unusual system crashes, unexpected reboots, or RTSP traffic patterns that deviate from established operational baselines.
Compensating Controls: Restrict access to the router management interface and disable unnecessary RTSP features if they are not required for specific network applications.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high severity and potential for total system compromise, administrators must prioritize the application of the vendor-supplied firmware updates. Ensure all regional variants are updated to the specified versions to eliminate the vulnerability and secure the network perimeter.