Executive brief
A security vulnerability exists in several TP-Link router models that could allow an authorized user to take complete control of the device. By uploading a specially crafted configuration file, an attacker can bypass security restrictions to run unauthorized commands with the highest level of system access. This could lead to the theft of network traffic, interception of data, or a total disruption of internet services.
Technical details
An OS command injection vulnerability (CWE-78) exists in the configuration import function of TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6. The flaw is caused by improper neutralization of special elements during the processing of port-trigger settings within a configuration file. An authenticated attacker with high privileges can exploit this by uploading a malicious configuration file, leading to the execution of arbitrary system commands as root. This results in full device compromise. Firmware updates have been released to address this issue.
Affected products
- TP-Link TL-WR802N v4 Before V4_260304
- TP-Link TL-WR841N v14 Before V14_260303
- TP-Link TL-WR840N v6 Before V6_260304
Timeline
- 2026-03-16: disclosed
- 2026-03-16: advisory
References
- https://www.tp-link.com/en/support/download/tl-wr802n/v4/
- https://www.tp-link.com/en/support/download/tl-wr840n/v6/
- https://www.tp-link.com/en/support/download/tl-wr841n/v14/
- https://www.tp-link.com/us/support/download/tl-wr802n/v4/
- https://www.tp-link.com/us/support/download/tl-wr841n/v14/
- https://www.tp-link.com/us/support/faq/5018/