CVE-2026-102294

Summary

TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands. 

Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.

Affected Software

VendorProductVersion RangeStatus
TP-Link System Inc.TL-WR841N v140 < 4.19 Build 260821 (EN)affected
TP-Link System Inc.TL-WR841N v140 < 4.19 Build 260820 (US)affected

Weaknesses

  • CWE-78: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References