Impact
This vulnerability is a stack-based buffer overflow (CWE‑121) located in the firmware update handling of the TL‑MR6400 v7.0. Unchecked metadata within a firmware image can corrupt memory, allowing an authenticated attacker to execute arbitrary code on the device.
Affected Systems
TP‑Link Systems Inc. TL‑MR6400 router, firmware version 7.0.
Risk and Exploitability
The vulnerability is rated CVSS 8.5 and is not listed in the KEV catalog. No EPSS score is available, indicating limited public exploitation data. Exploitation requires authenticated access to the firmware upload interface, making it a remote, authenticated attack that could compromise the device and potentially the local network.
OpenCVE Enrichment