CVE-2026-11409EPSS p85.0%

CVE-2026-11409CVE-2026-11409

tp-link / tl-wr940n_firmware

Description

An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.

Scoring

CVSS 7.2 ()
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS2.79% probability of exploitation · percentile 85.0% · 2026-08-03T12:00:16Z
Last modified2026-06-18
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.