Vulnerability Description
An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tl-Wr940N Firmware | < 260528 |
| Tp-Link | Tl-Wr940N | - |
Related Weaknesses (CWE)
References
- https://www.tp-link.com/en/support/download/tl-wr940n/v6/#FirmwareProduct
- https://www.tp-link.com/us/support/download/tl-wr940n/v6/#FirmwareProduct
- https://www.tp-link.com/us/support/faq/5131/Vendor Advisory
FAQ
What is CVE-2026-11410?
CVE-2026-11410 is a vulnerability with a CVSS score of 7.2 (HIGH). An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrati...
How severe is CVE-2026-11410?
CVE-2026-11410 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-11410?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tl-Wr940N Firmware, Tp-Link Tl-Wr940N.