OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-102294

HIGH · CVSS 8.5 EPSS 0.92% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

TP-Link TL-WR841N routers are vulnerable to an authenticated OS command injection in the IPv6 WAN configuration, where a crafted IPv6 Gateway value can lead to arbitrary command execution by an authenticated administrator. This vulnerability poses a high risk, as it could enable attackers to access sensitive information, alter device configurations, or disrupt services. Network administrators and organizations using this router model should prioritize immediate remediation to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102294
Severity
HIGH
CVSS
8.5
EPSS
0.92%

Original NVD Description

TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands.  Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.