The flaw is in the ated_tp service of TP-Link TL-WR841N. The service uses a user-supplied string in a system call without adequate validation of special elements, creating an OS command injection weakness classified as CWE-78.
The evidence supports the following high-level attack flow:
- A network-adjacent attacker supplies controlled data to a reachable component of the router.
ated_tp passes the insufficiently validated string into a system call.
- Arbitrary code executes in the context of
root.
The record does not disclose the specific request, parameter, protocol, or endpoint that must be reached. Do not infer a payload, path, or additional deployment condition beyond the presence of the affected component and network-adjacent reachability.