CVE-2026-102294: Authenticated OS Command Injection in TL-WR841N IPv6 WAN Configuration
TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands.
Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated as an administrator on the affected device. The vulnerable input is the IPv6 Gateway value in the IPv6 WAN configuration.
What can an attacker do after successful exploitation?
An authenticated administrator can execute arbitrary operating system commands on the device. This may expose sensitive information, alter device configuration or services, or disrupt device operation.