CVE-2025-15606 Details
Description
A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitization, allows crafted requests to trigger a processing error that causes the httpd service to crash. Successful exploitation may allow the attacker to cause service interruption, resulting in a DoS condition.
A denial-of-service vulnerability has been identified in the HTTPD component of the TP-Link TD-W8961N version 4.0. This vulnerability arises from improper input sanitization, allowing crafted requests to cause a processing error that crashes the HTTPD service. Exploitation of this vulnerability leads to a service interruption, creating a denial-of-service condition.
Users are advised to download and update to the latest firmware version. The latest firmware for the TD-W8961N V4 can be downloaded from the TP-Link official website. Instructions for upgrading the device are also available on the TP-Link website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/td-w8961n/v4/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5028/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-20 | Improper Input Validation | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link td-w8961nd firmware | < 250925 |
CPE
Remediation
| |
| tp-link td-w8961n | 4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | Initial Analysis | [email protected] |
| Mar 23, 2026 | New CVE Received | TPLink |