PT-2026-103951 · Tp Link Systems · Tl-Wr841N V14

CVE-2026-102294

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v4.0

8.5

High

VectorAV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands. 
Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102294

Affected Products

Tl-Wr841N V14