CVE-2026-8619
7.1
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process.
Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR100 v3.2 | 0 < TL-MR100(EU)_V3.20_1.3.0 Build 260609 Rel.49957n | affected |
| TP-Link Systems Inc. | TL-MR150 v.3.2 | 0 < TL-MR150(EU)_V3.20_1.3.0 Build 260720 Rel.59727n | affected |
| TP-Link Systems Inc. | TL-MR6400 v8.0 | 0 < TL-MR6400(EN)_V8_1.5.0 Build 260610 Rel.67978n | affected |
| TP-Link Systems Inc | Archer MR600 v2 | 0 < Archer MR600(EU)_V2_1.10.0 Build 260618 | affected |
Weaknesses
- CWE-476: CWE-476 NULL pointer dereference
References
- https://www.tp-link.com/en/support/download/archer-mr600/v2/#Firmware
- https://www.tp-link.com/en/support/download/tl-mr100/v3.20/#Firmware
- https://www.tp-link.com/en/support/download/tl-mr150/v3.20/#Firmware
- https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware
- https://www.tp-link.com/us/support/faq/5253/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.