VYPR

TL-WR940N

by TP-Link

CVEs (3)

  • CVE-2026-11410HigJun 17, 2026
    risk 0.47cvss 7.2epss 0.03

    An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with…

  • CVE-2026-11409HigJun 17, 2026
    risk 0.47cvss 7.2epss 0.03

    An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated…

  • CVE-2026-12935HigJul 29, 2026
    risk 0.00cvss —epss 0.01

    The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow. The issue occurs when a LAN client initiates a connection to a malicious RTSP server controlled by an attacker. A specially crafted RTSP…