Stack-based Out-of-Bounds Write Vulnerability in TP-Link TL-MR6400 Router
CVE-2026-17252

7.1HIGH

Key Information:

Vendor
CVE Published:
21 August 2026

What is CVE-2026-17252?

A stack-based out-of-bounds write vulnerability has been identified in the login request handling of the administrative web interface in TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can exploit this vulnerability by sending a specially crafted malformed HTTP request. If successfully exploited, this could lead to a crash of the web service process, resulting in a denial-of-service condition and temporarily disrupting access to the router's web management interface. It is essential for users to stay informed about potential risks and ensure their routers are updated with the latest firmware patches to mitigate this risk.

Affected Version(s)

TL-MR6400 v7.0 0 < 1.9.0 Build 260714

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rui Cheng Yu (Hina)
.