CVE-2025-6151: TP-Link TL-WR940N, TL-WR841N WanSlaacCfgRpm.htm buffer overflow
Published Jun 17, 2025
·Updated
A vulnerability has been found in TP-Link TL-WR940N V4 and TL-WR841N V11. Affected by this issue is some unknown functionality of the file /userRpm/WanSlaacCfgRpm.htm, which may lead to buffer overflow. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
2 affected components
All of the following
TP-Link Tl-wr940n Firmware
TP-Link TL-WR940N=v4
Event History
Jun 17, 2025
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
DescriptionWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Jan 16, 57510
Event
via FIRST·08:08 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-6151?
CVE-2025-6151 is classified as a critical vulnerability.
2
What devices are affected by CVE-2025-6151?
CVE-2025-6151 affects the TP-Link TL-WR940N version 4 router.
3
What type of vulnerability is CVE-2025-6151?
CVE-2025-6151 is a buffer overflow vulnerability.
4
How can CVE-2025-6151 be exploited?
CVE-2025-6151 can be exploited by manipulating the dnsserver1 argument in the /userRpm/WanSlaacCfgRpm.htm file.
5
How do I fix CVE-2025-6151?
To fix CVE-2025-6151, update the firmware of the TP-Link TL-WR940N to a version that addresses this vulnerability.