An
unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions
that may lead to a NULL pointer dereference.
A remote attacker on an adjacent network can send a specially crated
HTTP request to trigger a crash of the HTTP service process.
Successful
exploitation may cause the HTTP service to crash, making the web management
interface and HTTP-dependent functionality temporarily unavailable.
References
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
History
No history.
Information
Published : 2026-08-20 00:16
Updated : 2026-09-03 15:04
NVD link : CVE-2026-8619
Mitre link : CVE-2026-8619
CVE.ORG link : CVE-2026-8619
JSON object : View
Products Affected
tp-link
- tl-mr6400
- tl-mr100_firmware
- tl-mr6400_firmware
- archer_mr600_firmware
- tl-mr150
- tl-mr100
- tl-mr150_firmware
- archer_mr600
CWE
CWE-476
NULL Pointer Dereference
