CVE-2023-36355: TP-Link Tl-WR940N Firmware

Critical severity, CVSS 9.9. EPSS: 31.7% chance of exploitation in the next 30 days.

TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

Affected products

  • TP-Link Tl-WR940N Firmware: affected versions not specified

Published 2023-06-22. Last modified 2026-06-17.