
router.workdir: "/tmp/x; sh; #" That JSON value handed researcher MrBruh root on a TP-Link TL-MR6400 router. His writeup disclosed it as CVE-2026-3841. The bug lives in the Telnet management CLI's `cli` binary, specifically the `mdlog prepare` handler. It reads `router.workdir` from a conf.json file with cJSON, then blindly appends the value to a busybox tftp shell command without sanitization. With authenticated Telnet access over LAN, the attacker stands up a rogue TFTP server and serves a tampered conf.json embedding the payload. When the router fetches and processes the file for mdlog prep, the concatenated command executes: tftp aborts at the semicolon, sh launches a root shell, and the comment discards the trailing args. TP-Link patched the flaw on 12 Mar 2026. MrBruh's writeup "Finding a RCE in my old TP-Link router" went up 30 Apr 2026 after a 120-day disclosure window. The resulting shell was fully interactive, no further exploits needed. One unsanitized string turns a config pull into code exec.
Post summary
The writeup discloses a Remote Code Execution flaw in the router’s Telnet CLI, demonstrated via a tampered configuration file that executes a shell, and TP‑Link supplied a patch shortly thereafter.


