CVE-2026-11409

An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tl-wr940n_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr940n:v6:*:*:*:*:*:*:*

History

18 Jun 2026, 18:50

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 13:19

Updated : 2026-06-18 18:50


NVD link : CVE-2026-11409

Mitre link : CVE-2026-11409

CVE.ORG link : CVE-2026-11409


JSON object : View

Products Affected

tp-link

  • tl-wr940n
  • tl-wr940n_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')