SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76651

MEDIUM · CVSS 5.3 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects the embedded HTTP service in TL-WR841N v14, where insufficient validation of a boundary parameter in multipart/form-data requests can lead to a buffer overflow. This could allow a remote unauthenticated attacker to corrupt memory, potentially resulting in undefined application behavior. Organizations using this router model should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76651
Severity
MEDIUM
CVSS
5.3
EPSS
0.30%

Original NVD Description

A buffer overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing multipart/form-data requests. Insufficient validation of an attacker-controlled boundary parameter may allow a remote unauthenticated attacker to submit a crafted request that corrupts memory by overwriting data beyond the bounds of an internal buffer. Successful exploitation may result in modification or corruption of process memory, potentially leading to undefined application behavior. Arbitrary code execution, information disclosure, and denial-of-service conditions have not been demonstrated.