CVE-2026-8619 PUBLISHED

Unauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR150, TL-MR6400 and Archer MR600

Assigner: TPLink
Reserved: 14.05.2026 Published: 19.08.2026 Updated: 19.08.2026

An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference.  A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process.

Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor TP-Link Systems Inc.
Product TL-MR100 v3.2
Versions Default: unaffected
  • affected from 0 to TL-MR100(EU)_V3.20_1.3.0 Build 260609 Rel.49957n (excl.)
Vendor TP-Link Systems Inc.
Product TL-MR150 v.3.2
Versions Default: unaffected
  • affected from 0 to TL-MR150(EU)_V3.20_1.3.0 Build 260720 Rel.59727n (excl.)
Vendor TP-Link Systems Inc.
Product TL-MR6400 v8.0
Versions Default: unaffected
  • affected from 0 to TL-MR6400(EN)_V8_1.5.0 Build 260610 Rel.67978n (excl.)
Vendor TP-Link Systems Inc
Product Archer MR600 v2
Versions Default: unaffected
  • affected from 0 to Archer MR600(EU)_V2_1.10.0 Build 260618 (excl.)

Credits

  • haehet finder

References

Problem Types

  • CWE-476 NULL pointer dereference CWE

Impacts

  • CAPEC-125 Flooding