CVE-2025-14739 Details
Description
Access of Uninitialized Pointer vulnerability in TP-Link WR940N and WR941ND allows local unauthenticated attackers the ability to execute DoS attack and potentially arbitrary code execution under the context of the ‘root’ user.This issue affects WR940N and WR941ND: ≤ WR940N v5 3.20.1 Build 200316, ≤ WR941ND v6 3.16.9 Build 151203.
A vulnerability has been identified in TP-Link WR940N (V5) and WR941ND (V6) routers, allowing local unauthenticated attackers to access an uninitialized pointer. This vulnerability can be exploited to execute a denial-of-service attack and potentially execute arbitrary code with root privileges. The issue arises during the processing of UPnP/SOAP SUBSCRIBE requests.
Users are advised to update to the latest firmware version. For WR940N V5, the latest version is 3.20.1 Build 220801. For WR941ND V6, the latest version is 3.16.9 Build 151203.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 18, 2025CISA-ADP
Assessed Dec 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.exodusintel.com/2022/06/23/tp-link-wr940n-wr941nd-uninitialized-pointer-vulnerability/ | TPLink | AdvisoryTechnical Description |
| https://www.tp-link.com/us/support/download/tl-wr940n/v5/#Firmware | TPLink | ProductVendor |
| https://www.tp-link.com/us/support/download/tl-wr941nd/#Firmware | TPLink | ProductVendor |
| https://www.tp-link.com/us/support/faq/4848/ | TPLink | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-824 | Access of Uninitialized Pointer | TPLink |
Affected Products
| Product | Versions |
|---|---|
| TP-Link WR940N | All versions |
CPE
Remediation
| |
| TP-Link WR941ND | All versions |
CPE
Remediation
| |
| TP-Link WA850RE | All versions |
CPE
Remediation
| |
| TP-Link WA940N | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Dec 18, 2025 | New CVE Received | TPLink |
Volerion