CVE-2026-3622 Details
Description
The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-bounds read, potentially causing a crash of the UPnP service. Successful exploitation can cause the UPnP service to crash, resulting in a Denial-of-Service condition. This vulnerability affects TL-WR841N v14 < EN_0.9.1 4.19 Build 260303 Rel.42399n (V14_260303) and < US_0.9.1.4.19 Build 260312 Rel. 49108n (V14_0304).
A denial-of-service vulnerability has been identified in the UPnP component of the TP-Link TL-WR841N V14 router. This issue arises from improper input validation, leading to an out-of-bounds read that can cause the UPnP service to crash. The vulnerability affects versions prior to EN_0.9.1 4.19 Build 260303 Rel.42399n and US_0.9.1.4.19 Build 260312 Rel. 49108n.
Users are advised to download and update to the latest firmware version. The updated firmware can be downloaded from the TP-Link official website for both the English and US versions. As a temporary measure, UPnP can be disabled if operationally feasible.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/tl-wr841n/v14/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/download/tl-wr841n/v14/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5033/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link tl-wr841n firmware | < 0.9.1_4.19 |
CPE
Remediation
| |
| tp-link tl-wr841n | 14 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | New CVE Received | TPLink |