CVE-2026-11409
OS Command Injection in IPv6 PPPoE Configuration in TP-Link TL-WR940N
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
| CWE | CWE-78 |
| Vendor | tp-link systems inc. |
| Product | tl-wr940n v6 |
| Published | Jun 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link systems inc. tl-wr940n v6
Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. tl-wr940n v6 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TP-Link Systems Inc. / TL-WR940N v6
0 < V6_260528
References
Credits
Duong Ton Hoang Khang of Sacombank