CVE-2026-12935
Last modified
CVE-2026-12935 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow. The issue occurs when a LAN client initiates a connection to a malicious RTSP server controlled by an attacker.
Description
The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow. The issue occurs when a LAN client initiates a connection to a malicious RTSP server controlled by an attacker. A specially crafted RTSP message may trigger improper memory handling within the kernel module Successful exploitation of this vulnerability may result in a denial-of-service (DoS) condition or allow remote code execution (RCE), potentially leading to full compromise of the device. This vulnerability can be exploited by an unauthenticated attacker under the device's default configuration.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| TP-Link Systems Inc. | TL-WR940N v6 | < (US)_V6_260528; < (JP)_V6_260527; < (EU)_V6_260528 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-12935?
How severe is CVE-2026-12935?
How do I fix CVE-2026-12935?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12921In AzeoTech DAQFactory versions 21.1 and prior, a Use After …7.8
- CVE-2026-12923The Youtube Showcase plugin for WordPress is vulnerable to A…7.5
- CVE-2026-12924The Eventin – Event Calendar, Event Registration, Tickets & …6.4
- CVE-2026-12927CWE-787 Out-of-bounds write vulnerability exists that could …8.4
- CVE-2026-1293The Yoast SEO – Advanced SEO with real-time guidance and bui…6.4
- CVE-2026-12932A memory leak in the tls-crypt-v2 client key extraction in O…8.1
- CVE-2026-12936The Recurio – Ultimate Subscription for WooCommerce plugin f…4.9
- CVE-2026-12937The Tourfic – AI Powered Travel Booking, Hotel Booking & Car…7.5
- CVE-2026-12938The Newsletters Lite plugin for WordPress is vulnerable to S…6.4
- CVE-2026-12939The Newsletters Lite plugin for WordPress is vulnerable to S…6.4
- CVE-2026-1294The All In One Image Viewer Block plugin for WordPress is vu…7.2
- CVE-2026-12940IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to una…9.8
Are you affected by CVE-2026-12935?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
