Unauthenticated Denial-of-Service Vulnerability in TP-Link Routers
CVE-2026-8619

7.1HIGH

What is CVE-2026-8619?

An unauthenticated denial-of-service vulnerability has been discovered in several TP-Link router models, including TL-MR100, TL-MR150, TL-MR6400, and Archer MR600. This issue arises from the improper handling of exceptional request conditions, which may lead to a NULL pointer dereference. A remote attacker within an adjacent network could exploit this vulnerability by sending a specially crafted HTTP request, causing the HTTP service process to crash. As a result, the web management interface and other HTTP-dependent functionalities may become temporarily unavailable, impacting user access and service continuity.

Affected Version(s)

Archer MR600 v2 Linux 0

TL-MR100 v3.2 Linux 0

TL-MR150 v.3.2 Linux 0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

haehet
.