CVE-2026-3227PoC(tp-link / tl-wr802n)

MEDIUMCVSS 6.8 · MEDIUM

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch tp-link tl-wr802n systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in execution of OS commands with root privileges during port-trigger processing. Successful exploitation allows an authenticated attacker to execute system commands with root privileges, leading to full device compromise.

4.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tl-wr802n
  • tl-wr802n_firmware
  • tl-wr840n
  • tl-wr840n_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 8 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Discl: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-06-27); latest day: 3
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
tl-wr802ntl-wr802n_firmwaretl-wr840ntl-wr840n_firmwaretl-wr841ntl-wr841n_firmware

3 versions affected across 6 products

Deep dive

Activity timeline10 mentions / 5d
01223Mentions · 2026-03-13: 2Mentions · 2026-06-27: 3Mentions · 2026-06-28: 1Mentions · 2026-06-29: 1Mentions · 2026-07-17: 3PoC Mentioned / Linked · 2026-06-27: 3PoC Mentioned / Linked · 2026-06-28: 1PoC Mentioned / Linked · 2026-06-29: 1PoC Mentioned / Linked · 2026-07-17: 3Exploit Tool / Code · 2026-06-27: 3Exploit Tool / Code · 2026-06-29: 1Exploit Tool / Code · 2026-07-17: 2Patch / Workaround · 2026-06-27: 2Technical Details · 2026-03-13: 2Technical Details · 2026-06-27: 3Technical Details · 2026-07-17: 203-1306-2706-2806-2907-17
Signal classification4 categories
PoC
770.0%
Discl
110.0%
Disclosure
110.0%
General
110.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-132
Discl1Disclosure1
2026-06-273
PoC3
2026-06-281
General1
2026-06-291
PoC1
2026-07-173
PoC3
Full discourse10 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    🚨 CVE-2026-3227 PoC released for TP-Link routers https://github.com/do4choo/CVE-2026-3227 A public GitHub repo has been released for CVE-2026-3227, an authenticated OS command injection vulnerability affecting multiple TP-Link router models. The flaw exists in the router configuration backup / restore process and can allow an attacker with admin access to execute commands as root, potentially leading to full device compromise or persistent disruption. Repo includes: • Python PoC • QEMU hook tooling • Config payload generator • Root-cause analysis • Firmware reverse-engineering notes • Exploit workflow documentation Details: • Vendor: TP-Link • CVE: CVE-2026-3227 • Affected: TL-WR802N v4, TL-WR841N v14, TL-WR840N v6 • Type: Authenticated OS command injection • Impact: Root command execution • CWE: CWE-78 • Fixed versions: Latest TP-Link firmware releases Admins/Users should update affected TP-Link routers to the latest firmware.

    Post summary

    A Python PoC and related exploit materials for CVE-2026-3227 have been published on GitHub, highlighting an authenticated OS command injection in TP‑Link routers; administrators are urged to update to the latest firmware.

    91341263040376.3K
    226.8K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 #CVE-2026-3227 PoC Exploit Released: TP-Link Router Flaw Grants Root Access — Here’s How to Protect Your Network + Video https://undercodetesting.com/cve-2026-3227-poc-exploit-released-tp-link-router-flaw-grants-root-access-heres-how-to-protect-your-network-video/ Educational Purposes!

    Post summary

    The announcement reports a released PoC exploit for CVE-2026-3227 affecting TP‑Link routers, enabling root access, but offers no evidence of live attacks, patches, or detailed technical data.

    10021139
    715 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    A public GitHub repo has been released for CVE-2026-3227, an authenticated OS command injection vulnerability affecting multiple TP-Link router models.

    Post summary

    A public GitHub repository was released for CVE‑2026‑3227, providing a proof‑of‑concept and likely exploit code for an authenticated OS command‑injection vulnerability on multiple TP‑Link routers. No indication of active exploitation or a patch has been mentioned.

    1000031
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Source: X search for PoC exploit 2026 Posted: 2026-06-27T00:51:20.000Z Likes: 256 0day Intel: 🚨 CVE-2026-3227 PoC released for TP-Link routers

    Post summary

    A proof‑of‑concept for CVE‑2026‑3227 affecting TP‑Link routers has been released, but no exploitation tool, active attack evidence, patch details, or technical vulnerability specifics are provided.

    1000045
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-3227: 🚨 CVE-2026-3227 PoC released for TP-Link routers A public GitHub repo has been released for CVE-2026-3227, an authenticated OS command injection vulnerability affecting multiple TP-Link router models. The flaw exists in the router…

    Post summary

    A proof‑of‑concept exploiting an authenticated OS command injection in TP‑Link routers has been released on GitHub; there is no indication of active exploitation or a vendor patch yet.

    1000051
    326 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 TP-Link router'lar için CVE-2026-3227 PoC yayınlandı. TL-WR802N / WR841N / WR840N gibi modellerde, admin yetkisi olan bir saldırgan yedek config dosyasını manipüle ederek, geri yükleme sırasında root yetkisiyle çalışan OS komutları enjekte edebiliyor. https://github.com/do4choo/CVE-2026-3227

    Post summary

    A PoC has been released for CVE‑2026‑3227, showing that TP‑Link routers with admin access can inject OS commands via the backup configuration during restore, providing evidence of a local privilege escalation flaw.

    00010180
    1.1K followersView on X
  • motikan2010@motikan2010
    General

    2026-06-27 の人気記事はコチラでした。(自動ツイート) #Hacker_Trends ――― GitHub - do4choo/CVE-2026-3227 · GitHub https://hacker-trends.motikan2010.com/2026-06-27#d942b8962f90f78f7e5d845decc58d09 https://t.co/iQSMXUkEUs

    Post summary

    The tweet simply points to a popular article and a GitHub repository for CVE‑2026‑3227, offering no exploit details, patch information, or technical vulnerability specifics.

    00000138
    1.4K followersView on X
  • Juraj Cekan@JurajCekan
    PoC

    🚨 CVE-2026-3227 Public PoC released for this authenticated OS command injection in TP-Link TL-WR802N v4, TL-WR841N v14 & TL-WR840N v6. Crafted config.bin turns the backup/restore process into root command execution via clever QEMU hooks—because nothing says “fun Friday” like XML configs moonlighting as shell scripts. Thanks to @DarkWebInformer for surfacing this one. Since admin credentials are required, risk stays contained for well-managed devices. Patch promptly from official sources, use strong unique passwords, restrict management access, and follow basic IoT hygiene—simple habits that keep routers from becoming unexpected attack surfaces.

    Post summary

    A public PoC for an authenticated OS command injection in select TP‑Link routers has been released, detailing exploitation via a crafted config.bin and urging patching and secure management practices.

    0000085
    11 followersView on X
  • CVE@CVEnew
    Discl

    CVE-2026-3227 A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an … https://www.cve.org/CVERecord?id=CVE-2026-3227

    Post summary

    A brief CVE disclosure outlining a command injection flaw in TP‑Link routers; no PoC, exploit, or mitigation details are provided.

    00000112
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3227 - Authenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N Intel Report: https://ift.tt/io6G7cl

    Post summary

    The alert announces CVE-2026-3227, an authenticated command‑injection vulnerability affecting TP‑Link TL‑WR802N, TL‑WR841N, and TL‑WR840N routers, and directs readers to an Intel report for more details.

    0000027
    340 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linktl-wr802nv4--
OStp-linktl-wr802n_firmware---
HWtp-linktl-wr840n6--
OStp-linktl-wr840n_firmware---
HWtp-linktl-wr841n14--
OStp-linktl-wr841n_firmware---

Explore more