CVE-2026-3841 HIGH

CVE-2026-3841: Command Injection Vulnerability in Telnet CLI on TP-Link TL-MR6400

Vendor Tp-Link Systems Inc.
Product TL-MR6400 v5.3
Weakness CWE-78
Published March 12, 2026
Last update March 13, 2026

CVSS base score

8.5/10
Attack vector Adjacent
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient sanitization of data processed during specific CLI operations. An authenticated attacker with elevated privileges may be able to execute arbitrary system commands. Successful exploitation may lead to full device compromise, including potential loss of confidentiality, integrity, and availability.

Key dates

02Disclosure timeline

March 12, 2026 CVE published
March 13, 2026 Record updated