Impact
A stack‑based out‑of‑bounds write flaw exists in the login request handling of the TL‑MR6400 web management interface. When an unauthenticated attacker sends a specially crafted malformed HTTP request, the vulnerable code writes beyond a buffer boundary, causing the web service process to crash. The immediate consequence is a denial‑of‑service: the router’s web interface becomes temporarily unavailable until the service is restarted. The vulnerability is a classic example of memory corruption with the associated CWE‑787 weakness.
Affected Systems
The flaw affects TP‑Link Systems Inc. routers running the TL‑MR6400 model with firmware version 7.0. Only this specific version combination is known to be vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact if exploited. The episode can be triggered by any network host capable of reaching the device’s management port, as no authentication is required; the attack vector is inferred to be remote over the network. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, suggesting that the exploitation landscape is currently unclear. Nonetheless, given the simplicity of the trigger (a malformed HTTP request), the risk of a denial‑of‑service event in an environment with exposed management interfaces remains significant.
OpenCVE Enrichment