VendorsTP-Linktl-wr841n_firmwareany version
Vulnerabilities

TP-Link TL-WR841N router firmware any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2020-35576
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than CVE-2018-12577.
Published 2021-01-25 · Modified
9.01 PoCEPSS 0.423
CVE-2023-33538
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .
Published 2023-06-07 · Analyzed
8.8KEVEPSS 0.416
CVE-2022-46912
An issue in the firmware update process of TP-Link TL-WR841N / TL-WA841ND V7 3.13.9 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.
Published 2022-12-20 · Modified
8.8EPSS 0.010
CVE-2023-39471
TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.009
CVE-2023-36489
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: TL-WR802N firmware versions prior to 'TL-WR802N(JP)_V4_221008', TL-WR841N firmware versions prior to 'TL-WR841N(JP)_V14_230506', and TL-WR902AC firmware versions prior to 'TL-WR902AC(JP)_V3_230506'.
Published 2023-09-06 · Modified
8.8EPSS 0.006
CVE-2026-5039
Predictable Default Cryptographic Key Used for DES Encryption in TP-Link TL-WL841N
Published 2026-04-23 · Analyzed
8.8EPSS 0.002
CVE-2025-9377
Authenticated RCE via Parental Control command injection
Published 2025-08-29 · Analyzed
8.6KEVEPSS 0.335
CVE-2026-3227
Authenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N
Published 2026-03-13 · Analyzed
8.5EPSS 0.018
CVE-2023-33536
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/WlanMacFilterRpm.
Published 2023-06-07 · Modified
8.1EPSS 0.009
CVE-2023-33537
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/FixMapCfgRpm.
Published 2023-06-07 · Modified
8.1EPSS 0.009
CVE-2015-3035
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
Published 2015-04-17 · Analyzed
7.8KEVEPSS 0.839
CVE-2012-5687
Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.
Published 2012-11-01 · Modified
7.81 PoCEPSS 0.687
CVE-2023-36357
An issue in the /userRpm/LocalManageControlRpm component of TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8/V10, and TL-WR941ND V5 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
Published 2023-06-22 · Modified
7.7EPSS 0.008
CVE-2023-36356
TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8, TL-WR941ND V5, and TL-WR740N V1/V2 were discovered to contain a buffer read out-of-bounds via the component /userRpm/VirtualServerRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
Published 2023-06-22 · Modified
7.7EPSS 0.007
CVE-2023-36358
TP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR841N V8 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlAccessTargetsRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
Published 2023-06-22 · Modified
7.7EPSS 0.007
CVE-2023-36359
TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3 and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/QoSRuleListRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
Published 2023-06-22 · Modified
7.5EPSS 0.008
CVE-2023-36354
TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlTimeSchedRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
Published 2023-06-22 · Modified
7.5EPSS 0.008
CVE-2026-3622
Denial-of-Service Vulnerability in UPnP Component of TP Link's TL-WR841N
Published 2026-03-26 · Analyzed
7.5EPSS 0.007
CVE-2025-9014
Null Pointer Dereference Vulnerability on TL-WR841N
Published 2026-01-15 · Analyzed
7.5EPSS 0.005
CVE-2025-53711
TP-Link TL-WR841N, TL-WR842ND and TL-WR949N WlanNetworkRpm.htm buffer overflow
Published 2025-07-29 · Modified
7.5EPSS 0.003
CVE-2025-53712
TP-Link TL-WR841N WlanNetworkRpm_AP.htm buffer overflow
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2025-53713
TP-Link TL-WR841N WlanNetworkRpm_APC.htm buffer overflow
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2025-53714
TP-Link TL-WR841N WzdWlanSiteSurveyRpm_AP.htm buffer overflow
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2025-53715
TP-Link TL-WR841N Wan6to4TunnelCfgRpm.htm buffer overflow
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2026-9105
Authenticated Stack-Based Buffer Overflow in TP-Link TL-WR841N Web Interface
Published 2026-06-29 · Analyzed
6.8EPSS 0.011
CVE-2023-50224
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
6.5KEVEPSS 0.156
CVE-2012-6316
Multiple cross-site scripting (XSS) vulnerabilities in the TP-LINK TL-WR841N router with firmware 3.13.9 Build 120201 Rel.54965n and earlier allow remote administrators to inject arbitrary web script or HTML via the (1) username or (2) pwd parameter to userRpm/NoipDdnsRpm.htm.
Published 2014-09-30 · Modified
4.3EPSS 0.008