PT-2026-50084 · Tp Link Systems · Tl-Wr940N V6

Published

2026-06-16

·

Updated

2026-06-16

·

CVE-2026-11410

CVSS v4.0

8.5

High

VectorAV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11410

Affected Products

Tl-Wr940N V6