TL;DR
TP-Link patched a serious TP-Link TL-WR940N flaw, CVE-2026-12935. The bug allows unauthenticated remote code execution on the v6 router. It carries a CVSS 4.0 score of 8.7. No in-the-wild exploitation has been confirmed.
- CVE: CVE-2026-12935
- CVSS: 8.7 (High · CVSSv4)
- Product: TP-Link Systems Inc. TL-WR940N v6
- Affected: < (US)_V6_260528, < (JP)_V6_260527, < (EU)_V6_260528
- Impact: Unauthenticated Remote Code Execution in TP-Link TL-WR940N RTSP Conntrack Feature
- Status: No confirmed exploitation yet
- Patched in: (US)_V6_260528, (JP)_V6_260527, (EU)_V6_260528
- EPSS: 0.8% (30-day)
- Action: Update to (US)_V6_260528, (JP)_V6_260527, (EU)_V6_260528 now
Why it matters
Home and small-office routers guard the edge of a network. A full compromise there exposes every device behind it. So a pre-auth bug on a popular model is a real concern.
How the attack works
The flaw sits in the router’s RTSP connection tracking module. It can trigger a stack-based buffer overflow inside a kernel module. The trouble starts when a LAN client connects to a malicious RTSP server.
A crafted RTSP message then mishandles memory. According to TP-Link, a successful attack “may result in a denial-of-service (DoS) condition or allow remote code execution.” The vendor adds that it works “under the device’s default configuration.”
Affected versions
The bug affects the TP-Link TL-WR940N V6. Researchers at the University of Tsukuba and Powder Keg Technologies reported it. Only that hardware revision is listed.
Patch and mitigation
Update now. TP-Link released fixed firmware, build 260528 for EN and US, and 260527 for JP. Grab it from the vendor’s security advisory. Until you patch, avoid untrusted RTSP links to reduce exposure to this TP-Link TL-WR940N flaw.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.