Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-12935

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-121 Desbordamiendo de búfer basado en pila (Stack)
Fecha de publicación:
29/07/2026
Última modificación:
29/07/2026

Descripción

*** Pendiente de traducción *** The<br /> TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking<br /> module that can lead to a stack-based buffer overflow. The issue occurs when a<br /> LAN client initiates a connection to a malicious RTSP server controlled by an<br /> attacker. A specially crafted RTSP message may trigger improper memory handling<br /> within the kernel module<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation of this vulnerability may result in a denial-of-service (DoS)<br /> condition or allow remote code execution (RCE), potentially leading to full<br /> compromise of the device. This vulnerability can be exploited by an<br /> unauthenticated attacker under the device&amp;#39;s default configuration.