Sploitus

CVE-2026-3227

2 known exploits for CVE-2026-3227

A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in execution of OS commands with root privileges during port-trigger processing. Successful exploitation allows an authenticated attacker to execute system commands with root privileges, leading to full device compromise.

Tp-link tl-wr802n Firmware
< 260304
CVSS 4.0
8.5 HIGH
CVSS 3.1
6.8 MEDIUM
EPSS
1.9% (79th percentile)
Weakness
CWE-78
NVD status
Analyzed
Published
2026-03-13
Attack patterns
CAPEC-88
Entry point
filename binary
Path
cgi/confup
CVE-2026-3227 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-3227

Proof-of-concept code and exploit modules indexed by Sploitus