๐Ÿ” CVE Alert

CVE-2026-3841

UNKNOWN 0.0

Command Injection Vulnerability in Telnet CLI on TP-Link TL-MR6400

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient sanitization of data processed during specific CLI operations. An authenticated attacker with elevated privileges may be able to execute arbitrary system commands. Successful exploitation may lead to full device compromise, including potential loss of confidentiality, integrity, and availability.

CWE CWE-78
Vendor tp-link systems inc.
Product tl-mr6400 v5.3
Published Mar 12, 2026
Last Updated Mar 13, 2026
Stay Ahead of the Next One

Get instant alerts for tp-link systems inc. tl-mr6400 v5.3

Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. tl-mr6400 v5.3 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TP-Link Systems Inc. / TL-MR6400 v5.3
0 < 1.9.0 Build 260108

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
tp-link.com: https://www.tp-link.com/en/support/download/tl-mr6400/v5.30/#Firmware tp-link.com: https://www.tp-link.com/us/support/faq/5016/

Credits

MrBruh