Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation. | |
| Title | Authenticated OS Command Injection in TL-WR841N IPv6 WAN Configuration | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-10-01T17:48:24.216Z
Reserved: 2026-09-28T20:55:19.080Z
Link: CVE-2026-102294
Updated: 2026-10-01T17:48:19.479Z
Status : Received
Published: 2026-10-01T18:17:12.220
Modified: 2026-10-01T18:17:12.220
Link: CVE-2026-102294
No data.
OpenCVE Enrichment
No data.