---
id: CVE-2026-102294
title: >-
  TP-Link TL-WR841N contains an authenticated OS command injection vulnerability
  in the IPv6 WAN configuration
summary: >-
  TP-Link TL-WR841N contains an authenticated OS command injection vulnerability
  in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly
  incorporated into a system command, allowing an authenticated administrator to
  execu…
severity: high
cvss: 8.5
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-78
vendor: TP-Link System Inc.
product: TL-WR841N v14
affected:
  - tl-wr841n_v14 < 4.19 Build 260821 (EN)
  - tl-wr841n_v14 < 4.19 Build 260820 (US)
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T20:36:38.330'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102294'
references:
  - url: 'https://www.tp-link.com/en/support/download/tl-wr841n/v14/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/download/tl-wr841n/v14/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/faq/5320/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-01T17:48:15.761569Z'
cvssSource: cna
ingestedAt: '2026-10-01T18:55:42.367Z'
---

## Overview

TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands. 

Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
