CVE-2026-8619
EUVD-2026-6316820.08.2026, 00:16
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-mr100_firmware | 𝑥 < 1.3.0 |
| tp-link | archer_mr600_firmware | 𝑥 < 1.10.0 |
| tp-link | tl-mr150_firmware | 𝑥 < 1.3.0 |
| tp-link | tl-mr6400_firmware | 𝑥 < 1.5.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References