SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76650

MEDIUM · CVSS 5.3 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects the UPnP service in the TL-WR841N v14 router, allowing a specially crafted SOAP query to cause a NULL pointer dereference. This can lead to unexpected termination or instability of the UPnP service, resulting in a denial-of-service condition that disrupts UPnP discovery and management functions. Network administrators and users of the affected router model should prioritize this issue to maintain service availability and device stability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76650
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%

Original NVD Description

A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP state variable query requests. A specially crafted SOAP query may trigger unexpected termination or instability of the process hosting the UPnP service. Successful exploitation may result in a denial-of-service condition affecting UPnP discovery, state query, or related management functionality until the affected process is restarted or the device is rebooted.