Vulnerability Details CVE-2026-8619
An
unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions
that may lead to a NULL pointer dereference.
A remote attacker on an adjacent network can send a specially crated
HTTP request to trigger a crash of the HTTP service process.
Successful
exploitation may cause the HTTP service to crash, making the web management
interface and HTTP-dependent functionality temporarily unavailable.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 20.2%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-8619
-
cpe:2.3:h:tp-link:archer_mr600:2.0
-
cpe:2.3:h:tp-link:tl-mr100:3.2
-
cpe:2.3:h:tp-link:tl-mr150:3.2
-
cpe:2.3:h:tp-link:tl-mr6400:8.0
-
cpe:2.3:o:tp-link:archer_mr600_firmware:1.1.0
-
cpe:2.3:o:tp-link:tl-mr100_firmware:*
-
cpe:2.3:o:tp-link:tl-mr150_firmware:*
-
cpe:2.3:o:tp-link:tl-mr6400_firmware:*