Vulnerability Description
A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in execution of OS commands with root privileges during port-trigger processing. Successful exploitation allows an authenticated attacker to execute system commands with root privileges, leading to full device compromise.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tl-Wr802N Firmware | < 260304 |
| Tp-Link | Tl-Wr802N | v4 |
| Tp-Link | Tl-Wr841N Firmware | < 260303 |
| Tp-Link | Tl-Wr841N | 14 |
| Tp-Link | Tl-Wr840N Firmware | < 260304 |
| Tp-Link | Tl-Wr840N | 6 |
Related Weaknesses (CWE)
References
- https://www.tp-link.com/en/support/download/tl-wr802n/v4/#FirmwareProduct
- https://www.tp-link.com/en/support/download/tl-wr840n/v6/#FirmwareProduct
- https://www.tp-link.com/en/support/download/tl-wr841n/v14/#FirmwareProduct
- https://www.tp-link.com/us/support/download/tl-wr802n/v4/#FirmwareProduct
- https://www.tp-link.com/us/support/download/tl-wr841n/v14/#FirmwareProduct
- https://www.tp-link.com/us/support/faq/5018/Vendor Advisory
FAQ
What is CVE-2026-3227?
CVE-2026-3227 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router confi...
How severe is CVE-2026-3227?
CVE-2026-3227 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-3227?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tl-Wr802N Firmware, Tp-Link Tl-Wr802N, Tp-Link Tl-Wr841N Firmware, Tp-Link Tl-Wr841N, Tp-Link Tl-Wr840N Firmware.