← Vulnerability feed

Vulnerability record · CVE-2025-6151 · published 17 June 2025

CVE-2025-6151: Tp-link tl-wr940n firmware memory buffer overflow vulnerability

Tp Link · Tl Wr940n Firmware

A vulnerability has been found in TP-Link TL-WR940N V4 and TL-WR841N V11. Affected by this issue is some unknown functionality of the file /userRpm/WanSlaacCfgRpm.htm, which may lead to buffer overflow. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.

8.2 CVSS 4.0 High EPSS 5.0% · top 8.1% CWE-119 · Memory buffer overflowCWE-120 · Classic buffer overflow
8.2CVSS 4.0 base score
5.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability has been found in TP-Link TL-WR940N V4 and TL-WR841N V11. Affected by this issue is some unknown functionality of the file /userRpm/WanSlaacCfgRpm.htm, which may lead to buffer overflow. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/WhereisDoujo/CVE/issues/7 ExploitIssue TrackingThird Party Advisory
https://vuldb.com/?ctiid.312626 Permissions RequiredVDB Entry
https://vuldb.com/?id.312626 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.593031 Third Party AdvisoryVDB Entry
https://www.tp-link.com/us/support/faq/4536/
https://github.com/WhereisDoujo/CVE/issues/7 ExploitIssue TrackingThird Party Advisory

Track CVE-2025-6151 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-33538TP-Link router web interface command injection in WlanNetworkRpmTP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection flaw in the /userRpm/WlanNetworkRpm component of the route…KEVEPSS 42%analysed6.5CVE-2023-50224TP-Link router httpd authentication bypass exposes stored credentialsThe httpd service on affected TP-Link router firmware contains an improper authentication flaw (CWE-290) that lets a network-adjacent attacker bypass…KEVEPSS 16%analysed9.9CVE-2023-36355Tp-link tl-wr940n firmware classic buffer overflow vulnerabilityTP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allow…EPSS 32%8.8CVE-2022-43636Tp-link tl-wr940n firmware vulnerabilityThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) rout…EPSS 0.91%8.8CVE-2022-24355Tp-link tl-wr940n firmware stack-based buffer overflow vulnerabilityThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel…EPSS 2.1%8.8CVE-2019-6989Tp-link tl-wr940n firmware out-of-bounds write vulnerabilityTP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispose function. By sending specia…EPSS 11%8.5CVE-2026-11409Tp-link tl-wr940n firmware os command injection vulnerabilityAn authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of us…EPSS 2.8%8.5CVE-2026-11410Tp-link tl-wr940n firmware os command injection vulnerabilityAn authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper saniti…EPSS 2.8%

Source: NIST National Vulnerability Database (record CVE-2025-6151), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.