CVE-2026-3841 Details
Description
A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient sanitization of data processed during specific CLI operations. An authenticated attacker with elevated privileges may be able to execute arbitrary system commands. Successful exploitation may lead to full device compromise, including potential loss of confidentiality, integrity, and availability.
A command injection vulnerability exists in the Telnet command-line interface of the TP-Link TL-MR6400 router, specifically in version 5.3 prior to 1.9.0 Build 260108. This vulnerability arises from inadequate data sanitization during certain CLI operations, allowing an authenticated attacker with elevated privileges to execute arbitrary system commands. Exploitation of this vulnerability could lead to a complete compromise of the device.
Users are advised to upgrade to the latest firmware version available on the TP-Link official website for their region. The TL-MR6400 V5.3 firmware version 1.9.0 Build 260108 is the latest version that addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/tl-mr6400/v5.30/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5016/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link tl-mr6400 firmware | < 1.9.0 |
CPE
Remediation
| |
| tp-link tl-mr6400 | 5.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 2, 2026 | Initial Analysis | [email protected] |
| Mar 12, 2026 | New CVE Received | TPLink |