OS Command Injection Vulnerability in TP-Link TL-WR841N Router
CVE-2026-102294
8.5HIGH
What is CVE-2026-102294?
The TP-Link TL-WR841N router is susceptible to an authenticated OS command injection vulnerability within its IPv6 WAN configuration. This flaw allows an authenticated administrator to exploit a crafted IPv6 Gateway value, which is inadequately processed and integrated into system commands. As a result, attackers with valid access can execute arbitrary commands on the operating system. This exploitation could lead to unauthorized access to sensitive data, alterations to device settings, and potential service disruptions. Implement corrective measures promptly to safeguard against this vulnerability.
Affected Version(s)
TL-WR841N v14 0 < 4.19 Build 260821 (EN)
TL-WR841N v14 0 < 4.19 Build 260820 (US)
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Petar Knezevic <p.knezevic@gmx.ch>
