TP-LINK has released a patch for a critical vulnerability in the TL-WR940N router, identified as CVE-2026-12935, which allows unauthenticated remote code execution via a stack buffer overflow in the RTSP connection tracking module. The vulnerability has a CVSS score of 8.7 and affects specific firmware versions. Users are advised to update to patched versions to mitigate risks.
TPLink fixes CVE-2026-12935 bug in TLWR940N routers
CyberSIXT Evidence Panel
Article by CyberSIXT