Medium severity6.8NVD Advisory· Published Mar 16, 2026· Updated Apr 7, 2026
CVE-2026-3227
CVE-2026-3227
Description
A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in execution of OS commands with root privileges during port-trigger processing. Successful exploitation allows an authenticated attacker to execute system commands with root privileges, leading to full device compromise.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6Patches
Vulnerability mechanics
References
6- www.tp-link.com/us/support/faq/5018/nvdVendor Advisory
- www.tp-link.com/en/support/download/tl-wr802n/v4/nvdProduct
- www.tp-link.com/en/support/download/tl-wr840n/v6/nvdProduct
- www.tp-link.com/en/support/download/tl-wr841n/v14/nvdProduct
- www.tp-link.com/us/support/download/tl-wr802n/v4/nvdProduct
- www.tp-link.com/us/support/download/tl-wr841n/v14/nvdProduct
News mentions
0No linked articles in our index yet.