CVE 6.8 MEDIUM

Uninitialized Pointer Vulnerability in TP-Link WR940N and WR941ND_CVE-2025-14739

6.8 / 10
MEDIUM
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Description

Access of Uninitialized Pointer vulnerability in TP-Link WR940N and WR941ND allows local unauthenticated attackers the ability to execute DoS attack

and potentially arbitrary code execution

under the context of the ‘root’ user.This issue affects WR940N and WR941ND: ≤ WR940N v5 3.20.1 Build 200316,



WR941ND v6 3.16.9 Build 151203.

Basic Information

ID CVE-2025-14739
Source TPLink
Published Dec 18, 2025 at 18:02

Affected Product

Vendor TP-Link Systems Inc.
Product WR940N and WR941ND
Affected Versions TP-Link Systems Inc. WR940N and WR941ND 0
TP-Link Systems Inc. WR940N and WR941ND 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.