NULL Pointer Dereference in TP-Link TL-MR6400 Router
CVE-2026-17251

7.1HIGH

Key Information:

Vendor
CVE Published:
21 August 2026

What is CVE-2026-17251?

A NULL pointer dereference vulnerability has been identified in the HTTP request parsing functionality of the TL-MR6400 v7 router. An unauthenticated remote attacker can exploit this vulnerability by crafting a specially malformed HTTP request that includes an invalid session cookie header. If successfully executed, this can lead to the HTTP service process crashing, resulting in a denial-of-service condition that temporarily disrupts management and CGI functionality until the service is recovered.

Affected Version(s)

TL-MR6400 v7.0 Linux 0 < 1.9.0 Build 260714

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rui Cheng Yu (Hina)
.