CVE-2026-11410
TP-Link Systems Inc. TL-WR940N v6, tl-wr940n firmware, tl-wr940n
An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
- CVSS
- 8.5
- EPSS
- 2.79% 85.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.17