Junglewise Threat Intelligence

CVE-2026-11409: TP-Link TL-WR940N v6 command injection in IPv6 PPPoE handler

CVE-2026-11409 · Severity: info · CVSS 8.5 · Published 2026-06-17

Technologies: TP-Link TL-WR940N v6. Vendors: TP-Link.

Executive brief

A security vulnerability exists in the TP-Link TL-WR940N v6 wireless router, a device used to provide internet connectivity in homes and small offices. An attacker who has already gained administrative access to the router's management interface can take complete control of the device by injecting malicious commands through the IPv6 configuration settings. This could lead to the theft of sensitive information, modification of network traffic, or a total disruption of internet service.

Technical details

An OS command injection vulnerability (CWE-78) exists in the IPv6 PPPoE configuration handler of the TP-Link TL-WR940N v6 router. The flaw is caused by improper sanitization of user-supplied input within the WAN configuration module, where parameters are directly incorporated into system command execution. An attacker with high-privileged (administrative) credentials can exploit this via the web management interface from an adjacent network. Successful exploitation allows for arbitrary command execution with elevated privileges, potentially leading to full system compromise. TP-Link has released firmware version V6_260528 to address this issue, though the device is noted as reaching end-of-life (EOL).

Affected products

  • TP-Link TL-WR940N v6 Before V6_260528

Timeline

  • 2026-06-16: advisory: TP-Link published the security advisory.
  • 2026-06-17: disclosed: CVE published to NVD.

References

Related threats