CVE-2026-76651
Last modified
CVE-2026-76651 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A buffer overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing multipart/form-data requests. Insufficient validation of an attacker-controlled boundary parameter may allow a remote unauthenticated attacker to submit a crafted request that corrupts memory by overwriting data beyond the bounds of an internal buffer. Successful exploitation may result in modification or corruption of process memory, potentially leading to undefined application behavior. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
A buffer overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing multipart/form-data requests. Insufficient validation of an attacker-controlled boundary parameter may allow a remote unauthenticated attacker to submit a crafted request that corrupts memory by overwriting data beyond the bounds of an internal buffer. Successful exploitation may result in modification or corruption of process memory, potentially leading to undefined application behavior. Arbitrary code execution, information disclosure, and denial-of-service conditions have not been demonstrated.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| TP-Link System Inc. | TL-WR841N v14 | < TL-WR841N(US)_V14_4.19 Build 260820 Rel.33478; < TL-WR841N(EU)_V14_4.19 Build 260821 Rel.56588 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-76651?
How severe is CVE-2026-76651?
How do I fix CVE-2026-76651?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-76646A remote attacker could cause excessive resource consumption…7.5
- CVE-2026-76647Leantime JSON-RPC API through version 3.9.0 contains a missi…8.8
- CVE-2026-76648CopyAPIView (awx/awx/api/generics.py:873) sets permission_cl…8.5
- CVE-2026-76649A NULL pointer dereference vulnerability exists in TL-WR841N…5.3
- CVE-2026-7665The Essential Addons for Elementor – Popular Elementor Templ…5.3
- CVE-2026-76650A NULL pointer dereference vulnerability exists in TL-WR841N…5.3
- CVE-2026-76652An authenticated directory traversal vulnerability in file u…4.8
- CVE-2026-76653A missing authentication vulnerability in the VPN configurat…5.3
- CVE-2026-76657Vulnerabilities have been identified in the API of HPE Netwo…10
- CVE-2026-76658A vulnerability has been identified in the SSH daemon of HPE…10
- CVE-2026-7666An issue was discovered in Django 6.0 before 6.0.6 and 5.2 b…3.1
- CVE-2026-76669Privilege escalation vulnerabilities exist in the API of HPE…9.9
Are you affected by CVE-2026-76651?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
