CVE-2026-102294
Received Received - Intake

Authenticated OS Command Injection in TP-Link TL-WR841N

Vulnerability report for CVE-2026-102294, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: TPLink

Description

TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands.Β  Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
tp-link tl-wr841n 4.19_build_260821
tp-link tl-wr841n 4.19_build_260820

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authenticated OS command injection vulnerability in TP-Link TL-WR841N routers. It allows an authenticated administrator to execute arbitrary system commands by injecting a crafted IPv6 Gateway value into a system command. The flaw exists in the IPv6 WAN configuration of the device.

Detection Guidance

Detecting this vulnerability requires checking if your TL-WR841N router is running vulnerable firmware versions (v14 with firmware 4.19 Build 260821 (EN) or 4.19 Build 260820 (US)). Log in to the router's admin panel and navigate to the firmware version section to verify. Alternatively, use network scanning tools to identify devices with these firmware versions.

Impact Analysis

Exploitation may lead to unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation. Attackers with admin access could take control of the router, steal data, or cause service outages.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR and HIPAA. GDPR mandates strict protection of personal data, and HIPAA requires safeguarding protected health information. Exploitation of this flaw could result in unauthorized data exposure or modification, potentially leading to non-compliance with these regulations.

Mitigation Strategies

Immediately update the router's firmware to the latest version provided by TP-Link. Disable IPv6 WAN configuration if not required. Ensure strong administrative credentials are set and disable remote administration if unnecessary. Monitor network traffic for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102294. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart