PT-2025-7115 · Tp Link · Tp-Link Tl-Wr841Nd

Published

2025-02-04

·

Updated

2025-02-13

·

CVE-2025-25901

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: TP-Link TL-WR841ND version V11
Description: A buffer overflow issue was discovered, triggered by the dnsserver1 and dnsserver2 parameters at the "/userRpm/WanSlaacCfgRpm.htm" API endpoint. This allows attackers to cause a Denial of Service (DoS) via a crafted packet.
Recommendations: For TP-Link TL-WR841ND version V11, as a temporary workaround, consider restricting access to the "/userRpm/WanSlaacCfgRpm.htm" API endpoint to minimize the risk of exploitation. Avoid using the dnsserver1 and dnsserver2 parameters in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Improper Resource Release

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-01758
CVE-2025-25901

Affected Products

Tp-Link Tl-Wr841Nd