TP-Link, one of the world’s best-known router manufacturers, has acknowledged a serious security flaw in one of its most popular models, the TL-WR940N. The advisory, published at the end of July, warns that an attacker could take control of the device without needing to know the wifi password. We explain what happened and, above all, how to know if your router is one of those affected.
What a router is and why it matters that it’s healthy
The router is that box with little lights that distributes internet around the whole house. You could say it’s the postman of your connection: it receives the data that arrives from the line and delivers it to each device, whether it’s the computer, the phone or the TV. If someone manages to take control of that box, they can read what passes through it, change its settings or use it as a gateway to attack the other devices in your home. That’s why, when a router has a security hole, the news affects far more people than it seems.
The flaw: a glass that overflows
The vulnerability, registered as CVE-2026-12935, has a score of 8.7 out of 10, placing it at the “high” severity level. Technically it’s what experts call a buffer overflow: imagine a glass into which more water is poured than it can hold. The water spills and wets everything around it. Something similar happens with data: if more information is sent to the router than its memory can store, the excess “spills” and can allow the attacker to sneak their own commands into the device.
The curious thing about this case is the way the attacker gets in. The flaw is in the function the router uses to keep track of video streaming connections, the RTSP technology, widely used in security cameras and in some video players. For the attack to work, someone in the house has to click on a poisoned video link or connect to a streaming server controlled by the attacker. At that moment, the malicious server sends a special message to the router and it overflows.
What an attacker can do if they succeed
If they manage to exploit the flaw, the attacker could achieve several things, none of them pleasant:
- Leave the house without internet (what technicians call denial of service).
- Change the router’s configuration to redirect traffic or open back doors.
- Intercept data travelling across the home network.
- Install malicious programs that stay inside the router permanently.
- Use the router as a springboard to attack other connected devices, such as the computer or the phone.
The good news is that, according to TP-Link itself, no router password is needed to attempt it. The bad news is that a single click on the wrong link is enough. Even so, we should be fair: there’s no evidence that this flaw is already being used in mass attacks, so this is more a race to protect yourself in time than an alarm that your home is already in danger.
How to know if your router is the affected one
The flaw affects only a specific version of the TL-WR940N model: hardware version v6. To check, turn the router over and look for a sticker. There you’ll usually see the model and, next to it, something like “Ver: 6.0” or “TL-WR940N(UN)_V6”. If version 6 doesn’t appear, your device isn’t one of those affected by this particular flaw.
What to do if you have one of these routers
TP-Link has already published the fix in the form of a firmware update, which is the router’s internal program, something like the vaccine that protects it. The corrected versions end in 260528 (or 260527 for Japan). If your router is the affected one, go to the TP-Link support page, look for your model and download the latest update. The manufacturer itself explains the process step by step on its website.
In addition, there are two pieces of advice worth applying always, whatever router you have:
- Change the router’s administrator password to a long, unique one that you don’t use anywhere else. Many routers come with a default password that everyone knows.
- Be wary of video or streaming links that come to you from strangers, especially if they promise something too good, like watching a premiere for free.
The lesson: routers also need check-ups
The router is usually the great forgotten one in home security. We update the phone and the computer, but the box that distributes the internet goes years without a check-up. This advisory is a good reminder that the most discreet devices in the home also need care. If it’s been a long time since you last looked at yours, today can be a good day to do it: check the version, set a strong password and make sure it has the latest update. That’s ten minutes that can save you more than one headache.






