CVE-2026-12935
Severity CVSS v4.0:
HIGH
Type:
CWE-121
Stack-based Buffer Overflow
Publication date:
29/07/2026
Last modified:
29/07/2026
Description
The<br />
TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking<br />
module that can lead to a stack-based buffer overflow. The issue occurs when a<br />
LAN client initiates a connection to a malicious RTSP server controlled by an<br />
attacker. A specially crafted RTSP message may trigger improper memory handling<br />
within the kernel module<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
Successful<br />
exploitation of this vulnerability may result in a denial-of-service (DoS)<br />
condition or allow remote code execution (RCE), potentially leading to full<br />
compromise of the device. This vulnerability can be exploited by an<br />
unauthenticated attacker under the device&#39;s default configuration.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH



