7.5

CVE-2026-8619

Unauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR150, TL-MR6400 and Archer MR600

An
unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions
that may lead to a NULL pointer dereference. 
A remote attacker on an adjacent network can send a specially crated
HTTP request to trigger a crash of the HTTP service process.





Successful
exploitation may cause the HTTP service to crash, making the web management
interface and HTTP-dependent functionality temporarily unavailable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Tl-mr100 Firmware Version < 1.3.0
   Tp-link ≫ Tl-mr100 Version 3.2
Tp-link ≫ Archer Mr600 Firmware Version < 1.10.0
   Tp-link ≫ Archer Mr600 Version 2.0
Tp-link ≫ Tl-mr150 Firmware Version < 1.3.0
   Tp-link ≫ Tl-mr150 Version 3.2
Tp-link ≫ Tl-mr6400 Firmware Version < 1.5.0
   Tp-link ≫ Tl-mr6400 Version 8.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.207
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
f23511db-6c3e-4e32-a477-6aa17d310630 7.1 0 0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://www.tp-link.com/en/support/download/archer-mr600/v2/#Firmware
Product
https://www.tp-link.com/en/support/download/tl-mr100/v3.20/#Firmware
Product
https://www.tp-link.com/en/support/download/tl-mr150/v3.20/#Firmware
Product
https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware
Product
https://www.tp-link.com/us/support/faq/5253/
Vendor Advisory