HIGH 7.1 NVD
CVE-2026-17252
A stack-based out-of-bounds write vulnerability exists in the login request handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 r
A
stack-based out-of-bounds write vulnerability exists in the login request
handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability
by sending a specially crafted malformed HTTP request.
Successful
exploitation may cause the web service process to crash, resulting in a
denial-of-service condition and temporary loss of access to the router's web
management interface.
References
- https://www.tp-link.com/en/support/download/tl-mr6400/v7/#Firmware
- https://www.tp-link.com/tw/support/download/tl-mr6400/v7/#Firmware
- https://www.tp-link.com/us/support/faq/5259/
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-08-21 via NVD.
vulnfeed aggregates 11627 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.