Description
A
stack-based buffer overflow vulnerability exists in the firmware update
functionality of TL-MR6400 v7 due to unsafe processing of
attacker-controlled metadata within a firmware image.





Successful
exploitation may allow an authenticated attacker to trigger memory corruption
and execute arbitrary code on the affected device.
Published: 2026-08-21
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a stack-based buffer overflow (CWE‑121) located in the firmware update handling of the TL‑MR6400 v7.0. Unchecked metadata within a firmware image can corrupt memory, allowing an authenticated attacker to execute arbitrary code on the device.

Affected Systems

TP‑Link Systems Inc. TL‑MR6400 router, firmware version 7.0.

Risk and Exploitability

The vulnerability is rated CVSS 8.5 and is not listed in the KEV catalog. No EPSS score is available, indicating limited public exploitation data. Exploitation requires authenticated access to the firmware upload interface, making it a remote, authenticated attack that could compromise the device and potentially the local network.

Generated by OpenCVE AI on August 21, 2026 at 18:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from TP‑Link for the TL‑MR6400, ensuring the patched version has fixed the buffer overflow issue.
  • Restrict administrative and firmware update access to trusted IPs or local administrative networks, limiting exposure to authorized users only.
  • Monitor device logs for unusual firmware upload attempts and enforce least privilege for accounts with firmware update rights.

Generated by OpenCVE AI on August 21, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link tl-mr6400 V7
Vendors & Products Tp-link
Tp-link tl-mr6400 V7

Fri, 21 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlled metadata within a firmware image. Successful exploitation may allow an authenticated attacker to trigger memory corruption and execute arbitrary code on the affected device.
Title Authenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update Handling
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Tl-mr6400 V7
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-25T03:56:42.953Z

Reserved: 2026-07-24T22:03:10.608Z

Link: CVE-2026-17250

cve-icon Vulnrichment

Updated: 2026-08-21T17:40:55.960Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-21T18:16:47.450

Modified: 2026-08-28T19:02:53.760

Link: CVE-2026-17250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:15:23Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow