VendorsTP-Linktl-wr841n_firmwareall versions
Vulnerabilities

TP-Link TL-WR841N router firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

39CVEs
CVE-2018-11714
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.
Published 2018-06-04 · Modified
10.0EPSS 0.681
CVE-2022-25073
TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.
Published 2022-02-22 · Modified
10.0EPSS 0.130
CVE-2018-12575
On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of authentication via an HTTP request.
Published 2018-07-02 · Modified
9.8EPSS 0.029
CVE-2022-0162
Vulnerability in TP-LinK TL-WR841N wireless router
Published 2022-02-09 · Modified
9.8EPSS 0.007
CVE-2019-17147
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 80 by default. When parsing the Host request header, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length static buffer. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-8457.
Published 2020-01-07 · Modified
9.3EPSS 0.137
CVE-2020-35576
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than CVE-2018-12577.
Published 2021-01-25 · Modified
9.01 PoCEPSS 0.423
CVE-2020-8423
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the configuration of the Wi-Fi network.
Published 2020-04-02 · Modified
9.0EPSS 0.093
CVE-2023-33538
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .
Published 2023-06-07 · Analyzed
8.8KEVEPSS 0.416
CVE-2018-12577
The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow authenticated blind Command Injection.
Published 2018-07-02 · Modified
8.8EPSS 0.027
CVE-2022-30024
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network. This affects TL-WR841 V12 TL-WR841N(EU)_V12_160624 and TL-WR841 V11 TL-WR841N(EU)_V11_160325 , TL-WR841N_V11_150616 and TL-WR841 V10 TL-WR841N_V10_150310 are also affected.
Published 2022-07-14 · Modified
8.8EPSS 0.021
CVE-2022-46912
An issue in the firmware update process of TP-Link TL-WR841N / TL-WA841ND V7 3.13.9 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.
Published 2022-12-20 · Modified
8.8EPSS 0.010
CVE-2023-39471
TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.009
CVE-2023-36489
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: TL-WR802N firmware versions prior to 'TL-WR802N(JP)_V4_221008', TL-WR841N firmware versions prior to 'TL-WR841N(JP)_V14_230506', and TL-WR902AC firmware versions prior to 'TL-WR902AC(JP)_V3_230506'.
Published 2023-09-06 · Modified
8.8EPSS 0.006
CVE-2018-12574
CSRF exists for all actions in the web interface on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices.
Published 2018-07-02 · Modified
8.8EPSS 0.005
CVE-2026-5039
Predictable Default Cryptographic Key Used for DES Encryption in TP-Link TL-WL841N
Published 2026-04-23 · Analyzed
8.8EPSS 0.001
CVE-2025-9377
Authenticated RCE via Parental Control command injection
Published 2025-08-29 · Analyzed
8.6KEVEPSS 0.335
CVE-2026-3227
Authenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N
Published 2026-03-13 · Analyzed
8.5EPSS 0.019
CVE-2023-33537
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/FixMapCfgRpm.
Published 2023-06-07 · Modified
8.1EPSS 0.009
CVE-2023-33536
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/WlanMacFilterRpm.
Published 2023-06-07 · Modified
8.1EPSS 0.009
CVE-2015-3035
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
Published 2015-04-17 · Analyzed
7.8KEVEPSS 0.839
CVE-2012-5687
Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.
Published 2012-11-01 · Modified
7.81 PoCEPSS 0.687
CVE-2023-36357
An issue in the /userRpm/LocalManageControlRpm component of TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8/V10, and TL-WR941ND V5 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
Published 2023-06-22 · Modified
7.7EPSS 0.008
CVE-2023-36356
TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8, TL-WR941ND V5, and TL-WR740N V1/V2 were discovered to contain a buffer read out-of-bounds via the component /userRpm/VirtualServerRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
Published 2023-06-22 · Modified
7.7EPSS 0.007
CVE-2023-36358
TP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR841N V8 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlAccessTargetsRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
Published 2023-06-22 · Modified
7.7EPSS 0.007
CVE-2023-36359
TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3 and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/QoSRuleListRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
Published 2023-06-22 · Modified
7.5EPSS 0.008
CVE-2023-36354
TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlTimeSchedRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
Published 2023-06-22 · Modified
7.5EPSS 0.008
CVE-2025-9014
Null Pointer Dereference Vulnerability on TL-WR841N
Published 2026-01-15 · Analyzed
7.5EPSS 0.005
CVE-2026-3622
Denial-of-Service Vulnerability in UPnP Component of TP Link's TL-WR841N
Published 2026-03-26 · Analyzed
7.5EPSS 0.004
CVE-2025-53715
TP-Link TL-WR841N Wan6to4TunnelCfgRpm.htm buffer overflow
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2025-53714
TP-Link TL-WR841N WzdWlanSiteSurveyRpm_AP.htm buffer overflow
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2025-53713
TP-Link TL-WR841N WlanNetworkRpm_APC.htm buffer overflow
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2025-53712
TP-Link TL-WR841N WlanNetworkRpm_AP.htm buffer overflow
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2025-53711
TP-Link TL-WR841N, TL-WR842ND and TL-WR949N WlanNetworkRpm.htm buffer overflow
Published 2025-07-29 · Modified
7.5EPSS 0.003
CVE-2026-9105
Authenticated Stack-Based Buffer Overflow in TP-Link TL-WR841N Web Interface
Published 2026-06-29 · Analyzed
6.8EPSS 0.011
CVE-2023-50224
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
6.5KEVEPSS 0.156
CVE-2022-42202
TP-Link TL-WR841N 8.0 4.17.16 Build 120201 Rel.54750n is vulnerable to Cross Site Scripting (XSS).
Published 2022-10-18 · Modified
6.1EPSS 0.005
CVE-2012-6276
Directory traversal vulnerability in the web-based management interface on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via the URL parameter.
Published 2013-01-26 · Modified
4.31 PoCEPSS 0.035
CVE-2012-6316
Multiple cross-site scripting (XSS) vulnerabilities in the TP-LINK TL-WR841N router with firmware 3.13.9 Build 120201 Rel.54965n and earlier allow remote administrators to inject arbitrary web script or HTML via the (1) username or (2) pwd parameter to userRpm/NoipDdnsRpm.htm.
Published 2014-09-30 · Modified
4.3EPSS 0.008
CVE-2018-12576
TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking.
Published 2018-07-02 · Modified
4.3EPSS 0.007