CVE-2026-17250

Summary

A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlled metadata within a firmware image.

Successful exploitation may allow an authenticated attacker to trigger memory corruption and execute arbitrary code on the affected device.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.TL-MR6400 v7.00 < 1.9.0 Build 260714affected

Weaknesses

  • CWE-121: CWE-121 Stack-based buffer overflow

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References