TP-Link has announced a high-severity security vulnerability in its TL-WR940N v6 wireless router that could allow an unauthenticated remote attacker to execute arbitrary code and potentially take full control of the affected device.
This vulnerability is tracked as CVE-2026-12935 and has a CVSS v4.0 score of 8.7, categorized as high.
TP-Link TL-WR940N Router Flaw
According to TP-Link’s security advisory, the flaw is a stack-based buffer overflow in the router’s Real-Time Streaming Protocol (RTSP) connection-tracking feature.
The vulnerability can be triggered when a client on the local network connects to an attacker-controlled RTSP server. By responding with a specially crafted RTSP message, the malicious server may induce improper memory handling within the affected kernel module.
Successful exploitation of this vulnerability could lead to a denial-of-service condition, making the router unavailable, or allow for remote code execution.
An attacker who achieves code execution could potentially compromise the router, change network settings, intercept traffic, deploy persistent malware, or use the device as a foothold for attacks on other systems within the local network.
Importantly, exploitation of this vulnerability does not require authentication to the vulnerable router under its default configuration. However, user interaction is necessary, as a local network client must first connect to the malicious RTSP service.
This can happen if a victim accesses a malicious streaming link, connects to a rogue media endpoint, or uses an application that communicates with an attacker-controlled RTSP server.
TP-Link has assigned the following CVSS vector to CVE-2026-12935: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.
This rating reflects the flaw’s network-reachable attack path, low attack complexity, lack of authentication requirements, and the potentially severe impact on the affected router’s confidentiality, integrity, and availability.
This vulnerability specifically affects only the TP-Link TL-WR940N hardware version v6. TP-Link has addressed the issue in the following firmware updates: (EN)_V6_260528(EN), (US)_V6_260528(US), and (JP)_V6_260527(JP).
Users are encouraged to download and install the appropriate firmware package from the vendor’s regional support portal as soon as possible.
Organizations and home users operating the affected routers should limit access to untrusted streaming services, monitor connected devices for unusual activity, and ensure that router administration interfaces are secured with strong, unique passwords.
TP-Link credited Ryo Shimada of Powder Keg Technologies, Inc. for responsibly reporting the vulnerability, and the vendor published its advisory on July 30, 2026.
ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

