A newly disclosed vulnerability in TP-Link's TL-WR940N router allows unauthenticated attackers to execute remote code, putting millions of home and small-office networks at risk. Tracked as CVE-2026-12935, this flaw carries a CVSS score of 8.7 (High) and affects hardware version V6 with vulnerable firmware. Critical TP-Link Router Flaw As per the advisory, the flaw manifests as a stack-based buffer overflow when devices on the local network attempt to connect to an attacker-controlled malicious RTSP server.

Once connected, a specially crafted RTSP message triggers improper memory handling within the router's kernel module, corrupting the stack and allowing for arbitrary code execution.

The flaw can be exploited by an unauthenticated attacker without requiring credentials, prior access, or special privileges beyond convincing a LAN client to contact a hostile RTSP endpoint. Successful exploitation could lead to denial-of-service conditions at minimum or full remote code execution at worst, effectively giving an attacker complete control over the compromised device. Routers positioned at network perimeters and mediating inbound and outbound traffic make them prime targets for lateral movement, interception of traffic, or deployment of botnet malware.