CVE-2026-102294
Authenticated OS Command Injection in TL-WR841N IPv6 WAN Configuration
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands.ย Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.
| CWE | CWE-78 |
| Vendor | tp-link system inc. |
| Product | tl-wr841n v14 |
| Published | Oct 1, 2026 |
| Last Updated | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link system inc. tl-wr841n v14
Be the first to know when new unknown vulnerabilities affecting tp-link system inc. tl-wr841n v14 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TP-Link System Inc. / TL-WR841N v14
0 < 4.19 Build 260821 (EN) 0 < 4.19 Build 260820 (US)
References
Credits
Petar Knezevic <[email protected]>