Description
A
stack-based out-of-bounds write vulnerability exists in the login request
handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability
by sending a specially crafted malformed HTTP request.





Successful
exploitation may cause the web service process to crash, resulting in a
denial-of-service condition and temporary loss of access to the router's web
management interface.
Published: 2026-08-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A stack‑based out‑of‑bounds write flaw exists in the login request handling of the TL‑MR6400 web management interface. When an unauthenticated attacker sends a specially crafted malformed HTTP request, the vulnerable code writes beyond a buffer boundary, causing the web service process to crash. The immediate consequence is a denial‑of‑service: the router’s web interface becomes temporarily unavailable until the service is restarted. The vulnerability is a classic example of memory corruption with the associated CWE‑787 weakness.

Affected Systems

The flaw affects TP‑Link Systems Inc. routers running the TL‑MR6400 model with firmware version 7.0. Only this specific version combination is known to be vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact if exploited. The episode can be triggered by any network host capable of reaching the device’s management port, as no authentication is required; the attack vector is inferred to be remote over the network. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, suggesting that the exploitation landscape is currently unclear. Nonetheless, given the simplicity of the trigger (a malformed HTTP request), the risk of a denial‑of‑service event in an environment with exposed management interfaces remains significant.

Generated by OpenCVE AI on August 21, 2026 at 18:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest firmware for the TL‑MR6400 from TP‑Link that resolves the out‑of‑bounds write issue.
  • Disable or restrict remote access to the router’s web management interface so that only trusted LAN hosts can reach it.
  • Monitor router logs and uptime for repeated service crashes or restarts, and reboot the device as a temporary countermeasure if a crash occurs.

Generated by OpenCVE AI on August 21, 2026 at 18:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link tl-mr6400 V7
Vendors & Products Tp-link
Tp-link tl-mr6400 V7

Fri, 21 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description A stack-based out-of-bounds write vulnerability exists in the login request handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability by sending a specially crafted malformed HTTP request. Successful exploitation may cause the web service process to crash, resulting in a denial-of-service condition and temporary loss of access to the router's web management interface.
Title Unauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based Out-of-Bounds Write Vulnerability in TL-MR6400 Web Management Interface
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Tl-mr6400 V7
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-09-03T23:30:17.745Z

Reserved: 2026-07-24T22:03:13.178Z

Link: CVE-2026-17252

cve-icon Vulnrichment

Updated: 2026-08-21T17:38:33.250Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-21T18:16:47.803

Modified: 2026-08-28T19:02:53.760

Link: CVE-2026-17252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T20:30:07Z

Weaknesses