TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands.
Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.
Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation. | |
| Title | Authenticated OS Command Injection in TL-WR841N IPv6 WAN Configuration | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-10-01T17:48:24.216Z
Reserved: 2026-09-28T20:55:19.080Z
Link: CVE-2026-102294
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses