TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the context of the root user.
2025-01-09T20:15:39.277
2025-06-20T18:35:16.170
Analyzed
CVSSv3.1: 8.0 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | tp-link | tl-wr940n_firmware | ≤ 3.16.9 | Yes |
Hardware | tp-link | tl-wr940n | v3 | No |
Hardware | tp-link | tl-wr940n | v4 | No |