CVE-2026-3841

A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient sanitization of data processed during specific CLI operations. An authenticated attacker with elevated privileges may be able to execute arbitrary system commands. Successful exploitation may lead to full device compromise, including potential loss of confidentiality, integrity, and availability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tl-mr6400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-mr6400:5.3:*:*:*:*:*:*:*

History

02 Apr 2026, 13:03

Type Values Removed Values Added
CPE cpe:2.3:h:tp-link:tl-mr6400:5.3:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-mr6400_firmware:*:*:*:*:*:*:*:*
First Time Tp-link
Tp-link tl-mr6400 Firmware
Tp-link tl-mr6400
References () https://www.tp-link.com/en/support/download/tl-mr6400/v5.30/#Firmware - () https://www.tp-link.com/en/support/download/tl-mr6400/v5.30/#Firmware - Product
References () https://www.tp-link.com/us/support/faq/5016/ - () https://www.tp-link.com/us/support/faq/5016/ - Vendor Advisory
Summary
  • (es) Una vulnerabilidad de inyección de comandos ha sido identificada en la interfaz de línea de comandos (CLI) de Telnet de TP-Link TL-MR6400 v5.3. Este problema es causado por una sanitización insuficiente de los datos procesados durante operaciones específicas de la CLI. Un atacante autenticado con privilegios elevados podría ejecutar comandos de sistema arbitrarios. La explotación exitosa podría llevar a un compromiso total del dispositivo, incluyendo la posible pérdida de confidencialidad, integridad y disponibilidad.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

12 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-12 18:16

Updated : 2026-04-02 13:03


NVD link : CVE-2026-3841

Mitre link : CVE-2026-3841

CVE.ORG link : CVE-2026-3841


JSON object : View

Products Affected

tp-link

  • tl-mr6400_firmware
  • tl-mr6400
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')