CVE-2026-8619
Unauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR150, TL-MR6400 and Archer MR600
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference.ย A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.
| CWE | CWE-476 |
| Vendor | tp-link systems inc. |
| Product | tl-mr100 v3.2 |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link systems inc. tl-mr100 v3.2
Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. tl-mr100 v3.2 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TP-Link Systems Inc. / TL-MR100 v3.2
0 < TL-MR100(EU)_V3.20_1.3.0 Build 260609 Rel.49957n
TP-Link Systems Inc. / TL-MR150 v.3.2
0 < TL-MR150(EU)_V3.20_1.3.0 Build 260720 Rel.59727n
TP-Link Systems Inc. / TL-MR6400 v8.0
0 < TL-MR6400(EN)_V8_1.5.0 Build 260610 Rel.67978n
TP-Link Systems Inc / Archer MR600 v2
0 < Archer MR600(EU)_V2_1.10.0 Build 260618
References
tp-link.com: https://www.tp-link.com/en/support/download/archer-mr600/v2/#Firmware tp-link.com: https://www.tp-link.com/en/support/download/tl-mr100/v3.20/#Firmware tp-link.com: https://www.tp-link.com/en/support/download/tl-mr150/v3.20/#Firmware tp-link.com: https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware tp-link.com: https://www.tp-link.com/us/support/faq/5253/
Credits
haehet