TP-Link has disclosed a significant security vulnerability in its TL-WR940N V6 wireless router that poses a serious threat to users. The flaw, identified as CVE-2026-12935, enables remote code execution and denial-of-service attacks on affected devices. This vulnerability is a critical concern for both individual users and organizations relying on these routers for network connectivity.
Understanding the Vulnerability
The core issue resides in the router’s RTSP connection tracking feature. RTSP, or Real-Time Streaming Protocol, facilitates control over multimedia streaming. In this instance, the vulnerability stems from a stack-based buffer overflow within the RTSP kernel module. When excessively crafted data surpasses the allocated buffer, it leads to memory corruption.
Exploitation occurs when an attacker operates a malicious RTSP server, tricking a local network device into connecting. This connection can result in the delivery of harmful RTSP messages, which the vulnerable module incorrectly processes, causing memory corruption and potential remote code execution.
Implications of Remote Exploitation
Executing code remotely on the TL-WR940N V6 router has severe security implications. Attackers could manipulate network settings, intercept traffic, alter DNS configurations, or install persistent malware. Furthermore, compromised routers might serve as launch points for attacks on other network devices, amplifying the threat.
With a CVSS v4.0 score of 8.7, this vulnerability is classified as High risk. It has a network-based attack vector requiring minimal complexity and no authentication. However, exploitation necessitates user interaction, specifically a LAN client initiating contact with the rogue RTSP server.
Mitigation and Recommendations
TP-Link has addressed this issue by releasing firmware updates tailored to specific regions and hardware versions. Users should ensure their router’s hardware version and regional firmware match before installation. The updated firmware versions are (EN)_V6_260528 for English, (US)_V6_260528 for the US, and (JP)_V6_260527 for Japanese models.
Until updates are applied, users should restrict unnecessary RTSP connections and monitor for unusual network activity. This includes unexpected reboots or configuration changes indicative of potential exploitation attempts.
TP-Link acknowledges Ryo Shimada of Powder Keg Technologies, Inc. for the responsible disclosure of this vulnerability. Timely firmware updates remain the best defense against this threat, ensuring network safety.
