TP-Link TL-WR841N V14 UPnP Component Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the UPnP component of the TP-Link TL-WR841N V14 router. This issue arises from improper input validation, leading to an out-of-bounds read that can cause the UPnP service to crash. The vulnerability affects versions prior to EN_0.9.1 4.19 Build 260303 Rel.42399n and US_0.9.1.4.19 Build 260312 Rel. 49108n.

Impact

Exploitation of this vulnerability causes the UPnP service to crash, creating a denial-of-service condition on the device.

Remediation

Users are advised to download and update to the latest firmware version. The updated firmware can be downloaded from the TP-Link official website for both the English and US versions. As a temporary measure, UPnP can be disabled if operationally feasible.

Added: Mar 26, 2026, 9:21 PM
Updated: Mar 26, 2026, 9:21 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
0.6
exploitability
4.9
remediation
8.3
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.