Impact
TL-MR6400 v7.0 routers contain a null pointer dereference in the HTTP request parsing routine. An unauthenticated attacker can send a crafted HTTP request with a malformed session cookie header that causes the HTTP service process to crash, leading to a denial of service and temporary loss of management or CGI functionality.
Affected Systems
The affected device is the TP‑Link TL‑MR6400 router running firmware version 7.0. No other vendors or product versions are listed in the CNA data.
Risk and Exploitability
This flaw carries a CVSS score of 7.1, indicating medium‑to‑high severity, and the EPSS score is not available. The flaw is not listed in CISA’s KEV catalog. The attack vector is remote, unauthenticated, and requires only network access to the router’s HTTP interface. Because the vulnerability triggers on a malformed session cookie header, an attacker can repeatedly send crafted requests until the service crashes, after which the router’s management functions become unavailable until reboot or recovery.
OpenCVE Enrichment