CVE Database
/

CVE-2026-5039

Back to search

CVE-2026-5039

Published: Apr 23, 2026

Modified: Apr 28, 2026

PUBLISHED

Description

TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default web management credentials, making the key predictable if device is left in default configuration. A network-adjacent attacker can exploit this weakness to gain unauthorized access to the protocol, read debug data, modify certain device configuration values, and trigger device reboot, resulting in loss of integrity and a denial-of-service condition.

VendorProductVersions

TP-Link Systems Inc.

TL-WL841N v13

affected
0 - < 0.9.1 Build 20231120 Rel.62366

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now