Home

Description

A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitization, allows crafted requests to trigger a processing error that causes the httpd service to crash. Successful exploitation may allow the attacker to cause service interruption, resulting in a DoS condition.

PUBLISHED Reserved 2026-03-09 | Published 2026-03-23 | Updated 2026-03-24 | Assigner TPLink




HIGH: 7.1CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-20 Improper input validation

Product status

Default status
unaffected

Any version before V4_250925
affected

Credits

RONBUB finder

References

www.tp-link.com/en/support/download/td-w8961n/v4/ patch

www.tp-link.com/us/support/faq/5028/ vendor-advisory

cve.org (CVE-2025-15606)

nvd.nist.gov (CVE-2025-15606)

Download JSON