Vulnerability Intelligence Report
Authenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N
CVE-2026-3227
A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in execution of OS commands with root privileges during port-trigger processing. Successful exploitation allows an authenticated attacker to execute system commands with root privileges, leading to full device compromise.
No Active Exploit Signals
CVSS Base Score
8.5
HIGH
EPSS Probability:1.10%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| TP-Link Systems Inc. | TL-WR802N v4 | 0 < V4_260304 (affected) |
| TP-Link Systems Inc. | TL-WR841N v14 | 0 < V14_260303 (affected) |
| TP Link Systems Inc. | TL-WR840N v6 | 0 < V6_260304 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.102%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | TP-Link Systems Inc. · Vendor · USA |
| Reserved | 2026-02-25T20:03:19 |
| Published | 2026-03-13T21:38:31 |
| Last Updated | 2026-07-01T17:31:49 |
Community Chatter & Buzz