CVE-2025-9014: Null Pointer Dereference Vulnerability on TL-WR841N
A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input validation. A remote, unauthenticated attacker can exploit this flaw and cause Denial of Service on the web portal service.This issue affects TL-WR841N v14: before 250908.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9014?
CVE-2025-9014 is considered a high severity vulnerability due to its potential to cause Denial of Service.
How do I fix CVE-2025-9014?
To fix CVE-2025-9014, it is recommended to update the firmware of the TL-WR841N to the latest version released by TP-Link.
Who is affected by CVE-2025-9014?
CVE-2025-9014 affects TP-Link TL-WR841N devices running firmware version up to 250908.
Can CVE-2025-9014 be exploited remotely?
Yes, CVE-2025-9014 can be exploited remotely by an unauthenticated attacker.
What type of attack is associated with CVE-2025-9014?
CVE-2025-9014 is associated with a Null Pointer Dereference attack that can lead to Denial of Service.