Answer in brief
CVE-2026-102294 records a High severity (CVSS 8.5) vulnerability in Authenticated OS Command Injection in TL-WR841N IPv6 WAN Configuration. The current sources do not mark it as known exploited. The current feed maps TP-Link System Inc./TL-WR841N v14 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps TP-Link System Inc./TL-WR841N v14 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| TP-Link System Inc./TL-WR841N v14generic | >=0 <4.19 Build 260821 (EN) || >=0 <4.19 Build 260820 (US) | 4.19 Build 260821 (EN), 4.19 Build 260820 (US), 4.19 |
Published upstream
Oct 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 1, 2026
TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration or services, and disruption of device operation.
Quoted source text, attributed separately from HOL analysis.