An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/en/support/download/tl-wr940n/v6/#Firmware | Product |
| https://www.tp-link.com/us/support/download/tl-wr940n/v6/#Firmware | Product |
| https://www.tp-link.com/us/support/faq/5131/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
18 Jun 2026, 18:50
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-17 13:19
Updated : 2026-06-18 18:50
NVD link : CVE-2026-11409
Mitre link : CVE-2026-11409
CVE.ORG link : CVE-2026-11409
JSON object : View
Products Affected
tp-link
- tl-wr940n
- tl-wr940n_firmware
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
