CVE-2026-17252
TP-Link Systems Inc. TL-MR6400 v7.0
A stack-based out-of-bounds write vulnerability exists in the login request handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability by sending a specially crafted malformed HTTP request. Successful exploitation may cause the web service process to crash, resulting in a denial-of-service condition and temporary loss of access to the router's web management interface.
- CVSS
- 7.1
- EPSS
- 0.17% 6.66% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.22