CVE-2026-3841Disclosure(tp-link / tl-mr6400)

HIGHCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch tp-link tl-mr6400 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient sanitization of data processed during specific CLI operations. An authenticated attacker with elevated privileges may be able to execute arbitrary system commands. Successful exploitation may lead to full device compromise, including potential loss of confidentiality, integrity, and availability.

7.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tl-mr6400
  • tl-mr6400_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-12); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
tl-mr6400tl-mr6400_firmware

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-12: 1Mentions · 2026-04-16: 1Mentions · 2026-05-02: 1PoC Mentioned / Linked · 2026-05-02: 1Exploit Tool / Code · 2026-05-02: 1Active Exploitation · 2026-04-16: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-03-12: 1Technical Details · 2026-05-02: 103-1204-1605-02
Signal classification3 categories
Disclosure
133.3%
Active Exploitation
133.3%
PoC
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-121
Disclosure1
2026-04-161
Active Exploitation1
2026-05-021
PoC1
Full discourse3 posts
  • SecureChap@SecureChap
    PoC

    router.workdir: "/tmp/x; sh; #" That JSON value handed researcher MrBruh root on a TP-Link TL-MR6400 router. His writeup disclosed it as CVE-2026-3841. The bug lives in the Telnet management CLI's `cli` binary, specifically the `mdlog prepare` handler. It reads `router.workdir` from a conf.json file with cJSON, then blindly appends the value to a busybox tftp shell command without sanitization. With authenticated Telnet access over LAN, the attacker stands up a rogue TFTP server and serves a tampered conf.json embedding the payload. When the router fetches and processes the file for mdlog prep, the concatenated command executes: tftp aborts at the semicolon, sh launches a root shell, and the comment discards the trailing args. TP-Link patched the flaw on 12 Mar 2026. MrBruh's writeup "Finding a RCE in my old TP-Link router" went up 30 Apr 2026 after a 120-day disclosure window. The resulting shell was fully interactive, no further exploits needed. One unsanitized string turns a config pull into code exec.

    Post summary

    The writeup discloses a Remote Code Execution flaw in the router’s Telnet CLI, demonstrated via a tampered configuration file that executes a shell, and TP‑Link supplied a patch shortly thereafter.

    0100077
    55 followersView on X
  • Solomon Neas@solomonneas
    Active Exploitation

    🔴 Nginx UI CVE-2026-3841 is under active exploitation, patch now. 🟡 Microsoft fixed an exploited SharePoint flaw in April Patch Tuesday. 🟡 Trusted n8n cloud webhooks are being abused for phishing and malware delivery. http://solomonneas.dev/intel

    Post summary

    Nginx UI CVE‑2026‑3841 is actively exploited in the wild and a patch is now available; additional exploits are noted for SharePoint and n8n webhooks, but no PoC or detailed tool is provided.

    0001062
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3841 A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient saniti… https://www.cve.org/CVERecord?id=CVE-2026-3841

    Post summary

    The text announces the discovery of CVE-2026-3841, a command injection flaw in the TP‑Link TL‑MR6400 v5.3 Telnet CLI, with no evidence of exploitation, patches, or false‑positive claims.

    00000151
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linktl-mr64005.3--
OStp-linktl-mr6400_firmware---

Explore more