CVE-2026-9105: Authenticated Stack-Based Buffer Overflow in TP-Link TL-WR841N Web Interface
An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests to cause the embedded web server to overflow a stack buffer, resulting in a crash of the affected process.
Successful exploitation results in a denial-of-service condition, causing the device to crash and automatically reboot.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9105?
The severity of CVE-2026-9105 is classified as medium with a CVSS score of 6.8.
How do I fix CVE-2026-9105?
To fix CVE-2026-9105, users should update the firmware of the TP-Link TL-WR841N to the latest version available from the manufacturer.
What are the risks associated with CVE-2026-9105?
CVE-2026-9105 allows an authenticated attacker to exploit a stack-based buffer overflow, potentially causing a crash of the web management interface.
Which devices are affected by CVE-2026-9105?
CVE-2026-9105 affects the TP-Link TL-WR841N, specifically version 14 of its firmware.
Can CVE-2026-9105 be exploited remotely?
Yes, CVE-2026-9105 can be exploited remotely by an authenticated attacker through crafted HTTP requests.