CVE-2026-17250
Authenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update Handling
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlled metadata within a firmware image. Successful exploitation may allow an authenticated attacker to trigger memory corruption and execute arbitrary code on the affected device.
| CWE | CWE-121 |
| Vendor | tp-link systems inc. |
| Product | tl-mr6400 v7.0 |
| Published | Aug 21, 2026 |
| Last Updated | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link systems inc. tl-mr6400 v7.0
Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. tl-mr6400 v7.0 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TP-Link Systems Inc. / TL-MR6400 v7.0
0 < 1.9.0 Build 260714
References
Credits
Rui Cheng Yu (Hina)