{"id":"CVE-2026-3227","title":"A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command","summary":"A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command.  In the router configuration import function allows an au…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"tp-link","product":"tl-wr802n_firmware","affected":["tl-wr802n_firmware < 260304","tl-wr841n_firmware < 260303","tl-wr840n_firmware < 260304"],"patched":["tl-wr802n_firmware 260304","tl-wr841n_firmware 260303","tl-wr840n_firmware 260304"],"published":"2026-03-16","updated":"2026-07-01","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-3227","references":[{"url":"https://www.tp-link.com/en/support/download/tl-wr802n/v4/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/en/support/download/tl-wr840n/v6/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/en/support/download/tl-wr841n/v14/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/tl-wr802n/v4/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/tl-wr841n/v14/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/5018/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd","exploit-available"],"epss":0.01935,"epssPercentile":0.78903,"ingestedAt":"2026-07-01T09:50:45.458Z","exploits":{"github":1,"githubRepos":["https://github.com/do4choo/CVE-2026-3227-TP-Link-authenticated-RCE"],"checkedAt":"2026-09-21T15:28:40.907Z"},"exploitAvailable":true,"slug":"CVE-2026-3227","body":"## Overview\n\nA command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command.  In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in execution of OS commands with root privileges during port-trigger processing.  \nSuccessful exploitation allows an authenticated attacker to execute system commands with root privileges, leading to full device compromise.\n\n## Affected\n\n- `tl-wr802n_firmware < 260304`\n- `tl-wr841n_firmware < 260303`\n- `tl-wr840n_firmware < 260304`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `tl-wr802n_firmware 260304`\n- `tl-wr841n_firmware 260303`\n- `tl-wr840n_firmware 260304`","depth":"twilight","depthScore":50,"depthScoreParts":{"impact":37.4,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[{"seq":5081,"id":"CVE-2026-3227","ts":1788887247986,"field":"exploit_available","old":"false","new":"true"},{"seq":3964,"id":"CVE-2026-3227","ts":1788886363625,"field":"exploit_available","old":"true","new":"false"},{"seq":2785,"id":"CVE-2026-3227","ts":1788883030332,"field":"exploit_available","old":"false","new":"true"},{"seq":1814,"id":"CVE-2026-3227","ts":1788882433247,"field":"exploit_available","old":"true","new":"false"},{"seq":918,"id":"CVE-2026-3227","ts":1788881866990,"field":"exploit_available","old":"false","new":"true"}]}