Executive brief
A security vulnerability has been identified in the TP-Link TL-WR940N v6 wireless router, a device used to provide internet connectivity in homes and small offices. An attacker with administrative access to the router's management interface can execute unauthorized system commands by exploiting a flaw in the BigPond Cable (BPA) configuration settings. This could allow an attacker to take full control of the device, potentially leading to data interception, network disruption, or further attacks on connected devices.
Technical details
An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module of the TP-Link TL-WR940N v6 router. The flaw is caused by improper sanitization of user-supplied parameters within the web management interface, which are subsequently used to construct system commands. An attacker with high privileges (administrative access) can exploit this via the adjacent network to execute arbitrary system commands with elevated privileges. This can result in a total compromise of confidentiality, integrity, and availability. TP-Link has released firmware version V6_260528 to address this issue, though the device is noted as reaching end-of-life (EOL).
Affected products
- TP-Link TL-WR940N v6 before V6_260528
Timeline
- 2026-06-16: advisory: TP-Link published security advisory
- 2026-06-17: disclosed: NVD publication date