---
id: CVE-2026-3227
title: >-
  A command injection vulnerability was identified in TP-Link TL-WR802N v4,
  TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special
  elements used in an OS command
summary: >-
  A command injection vulnerability was identified in TP-Link TL-WR802N v4,
  TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special
  elements used in an OS command.  In the router configuration import function
  allows an au…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: tp-link
product: tl-wr802n_firmware
affected:
  - tl-wr802n_firmware < 260304
  - tl-wr841n_firmware < 260303
  - tl-wr840n_firmware < 260304
patched:
  - tl-wr802n_firmware 260304
  - tl-wr841n_firmware 260303
  - tl-wr840n_firmware 260304
published: '2026-03-16'
updated: '2026-07-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-3227'
references:
  - url: 'https://www.tp-link.com/en/support/download/tl-wr802n/v4/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/en/support/download/tl-wr840n/v6/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/en/support/download/tl-wr841n/v14/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/download/tl-wr802n/v4/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/download/tl-wr841n/v14/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/faq/5018/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
  - exploit-available
epss: 0.01935
epssPercentile: 0.78903
ingestedAt: '2026-07-01T09:50:45.458Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/do4choo/CVE-2026-3227-TP-Link-authenticated-RCE'
  checkedAt: '2026-09-21T15:28:40.907Z'
exploitAvailable: true
---

## Overview

A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command.  In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in execution of OS commands with root privileges during port-trigger processing.  
Successful exploitation allows an authenticated attacker to execute system commands with root privileges, leading to full device compromise.

## Affected

- `tl-wr802n_firmware < 260304`
- `tl-wr841n_firmware < 260303`
- `tl-wr840n_firmware < 260304`

## Remediation

Upgrade past the affected range:

- `tl-wr802n_firmware 260304`
- `tl-wr841n_firmware 260303`
- `tl-wr840n_firmware 260304`
