CVE-2026-11410: TP-Link Tl-WR940N Firmware
High severity, CVSS 7.2. EPSS: 2.8% chance of exploitation in the next 30 days.
An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
Affected products
- TP-Link Tl-WR940N Firmware: before 260528 (fixed in 260528)
Published 2026-06-17. Last modified 2026-06-18.