Description
A NULL
pointer dereference vulnerability exists in the HTTP request parsing
functionality of 
TL-MR6400 v7. An unauthenticated remote attacker can
trigger the vulnerability by sending a specially crafted HTTP request
containing a malformed session cookie header.





Successful
exploitation may cause the HTTP service process to crash, resulting in a
denial-of-service condition and temporary loss of management or CGI
functionality until service recovery.
Published: 2026-08-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via HTTP service crash
Action: Apply Firmware Update
AI Analysis

Impact

TL-MR6400 v7.0 routers contain a null pointer dereference in the HTTP request parsing routine. An unauthenticated attacker can send a crafted HTTP request with a malformed session cookie header that causes the HTTP service process to crash, leading to a denial of service and temporary loss of management or CGI functionality.

Affected Systems

The affected device is the TP‑Link TL‑MR6400 router running firmware version 7.0. No other vendors or product versions are listed in the CNA data.

Risk and Exploitability

This flaw carries a CVSS score of 7.1, indicating medium‑to‑high severity, and the EPSS score is not available. The flaw is not listed in CISA’s KEV catalog. The attack vector is remote, unauthenticated, and requires only network access to the router’s HTTP interface. Because the vulnerability triggers on a malformed session cookie header, an attacker can repeatedly send crafted requests until the service crashes, after which the router’s management functions become unavailable until reboot or recovery.

Generated by OpenCVE AI on August 21, 2026 at 18:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest TP‑Link release that addresses the HTTP parsing issue.
  • If an immediate firmware update is not possible, restrict external access to the router’s HTTP management interface to a trusted internal network.
  • Continuously monitor the device’s logs for repeated HTTP errors and consider disabling the HTTP management service until a patch is applied.

Generated by OpenCVE AI on August 21, 2026 at 18:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link tl-mr6400 V7
Vendors & Products Tp-link
Tp-link tl-mr6400 V7

Fri, 21 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of  TL-MR6400 v7. An unauthenticated remote attacker can trigger the vulnerability by sending a specially crafted HTTP request containing a malformed session cookie header. Successful exploitation may cause the HTTP service process to crash, resulting in a denial-of-service condition and temporary loss of management or CGI functionality until service recovery.
Title Unauthenticated Denial of Service via Null Pointer Dereference in HTTP Request Parsing
Weaknesses CWE-476
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Tl-mr6400 V7
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-21T17:40:36.098Z

Reserved: 2026-07-24T22:03:11.872Z

Link: CVE-2026-17251

cve-icon Vulnrichment

Updated: 2026-08-21T17:40:31.686Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-21T18:16:47.660

Modified: 2026-08-28T19:02:53.760

Link: CVE-2026-17251

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T20:30:07Z

Weaknesses