Severity
High
Analysis Summary
TP-Link has disclosed a high-severity security vulnerability (CVE-2026-12935) affecting the TL-WR940N V6 wireless router. The flaw exists in the router's RTSP (Real-Time Streaming Protocol) connection tracking (conntrack) module, which processes RTSP traffic within the Linux kernel. Due to a stack-based buffer overflow, specially crafted RTSP responses can corrupt kernel memory, potentially causing a denial-of-service (DoS) condition or enabling remote code execution (RCE) under specific conditions. The vulnerability carries a CVSS v4.0 score of (High), features a network attack vector, requires no authentication, but does require user interaction, as a device on the local network must first connect to an attacker-controlled RTSP server.
The attack scenario involves an attacker operating a malicious RTSP server and persuading a LAN-connected device to initiate an RTSP session with it. The malicious server then returns specially crafted RTSP messages that are improperly handled by the router's vulnerable conntrack component, leading to kernel memory corruption. Successful exploitation can crash the router, disrupting network availability, or allow attackers to execute arbitrary code on the device. A compromised router could be used to modify network configurations, alter DNS settings, intercept or redirect network traffic, install persistent malware, and launch attacks against other systems on the local network, making the vulnerability particularly dangerous despite the required user interaction.
The vulnerability specifically impacts TP-Link TL-WR940N hardware version V6, and TP-Link has released patched firmware versions (EN)_V6_260528, (US)_V6_260528, and (JP)_V6_260527 for the respective regional models. Users are advised to verify both their hardware revision and regional firmware version before updating, as installing firmware intended for another region may cause device instability or malfunction. Until patches are applied, organizations and home users should restrict unnecessary outbound RTSP connections, monitor for unusual RTSP traffic, unexpected router reboots, and unauthorized configuration changes, and download firmware only from TP-Link's official support portal. The vulnerability was responsibly disclosed by Ryo Shimada of Powder Keg Technologies, Inc., with timely firmware updates serving as the primary mitigation against CVE-2026-12935.
Impact
- Denial of Service
- Code Execution
- Gain Access
Indicators of Compromise
CVE
- CVE-2026-12935
Remediation
- Update immediately to the latest TP-Link firmware for your TL-WR940N V6 router using the official TP-Link support portal.
- Verify the router's hardware version and regional firmware (EN, US, or JP) before installing updates to avoid compatibility or device malfunction issues.
- Restrict unnecessary outbound RTSP (Real-Time Streaming Protocol) connections from devices on the local network until the firmware update is applied.
- Monitor network traffic for unusual RTSP activity that could indicate attempted exploitation.
- Watch for unexpected router reboots, crashes, or unauthorized configuration changes, such as modified DNS settings, which may signal compromise.
- Download firmware only from TP-Link's official website and avoid installing firmware from untrusted or third-party sources.
- Regularly review router configurations and logs to identify suspicious activity and ensure security settings remain unchanged.
- Replace or isolate unsupported/end-of-life devices if security updates are no longer available for the affected hardware.