SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76649

MEDIUM · CVSS 5.3 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A NULL pointer dereference vulnerability in the UPnP service of TL-WR841N v14 can be exploited through specially crafted SOAP action requests, leading to unexpected termination of the UPnP daemon. This results in a denial-of-service condition that disrupts UPnP functionality until the service is restarted or the device is rebooted. Users of affected devices, particularly those relying on UPnP for network services, should prioritize addressing this vulnerability to maintain service availability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76649
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%

Original NVD Description

A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action requests. A specially crafted SOAP action request containing unexpected XML content may cause the UPnP daemon to terminate unexpectedly. Successful exploitation may result in a denial-of-service condition affecting UPnP functionality until the service is restarted or the device is rebooted.