๐Ÿ” CVE Alert

CVE-2026-102294

UNKNOWN 0.0

Authenticated OS Command Injection in TL-WR841N IPv6 WAN Configuration

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands.ย  Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.

CWE CWE-78
Vendor tp-link system inc.
Product tl-wr841n v14
Published Oct 1, 2026
Last Updated Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for tp-link system inc. tl-wr841n v14

Be the first to know when new unknown vulnerabilities affecting tp-link system inc. tl-wr841n v14 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TP-Link System Inc. / TL-WR841N v14
0 < 4.19 Build 260821 (EN) 0 < 4.19 Build 260820 (US)

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
tp-link.com: https://www.tp-link.com/en/support/download/tl-wr841n/v14/#Firmware tp-link.com: https://www.tp-link.com/us/support/download/tl-wr841n/v14/#Firmware tp-link.com: https://www.tp-link.com/us/support/faq/5320/

Credits

Petar Knezevic <[email protected]>