Executive brief
The TL-MR6400 is a 4G LTE router used by businesses and consumers to provide wireless internet connectivity. A stack-based buffer overflow in its firmware update mechanism could allow an authenticated attacker with access to the device to execute arbitrary code and take complete control of the router, potentially compromising all traffic passing through it or launching further attacks on connected networks.
Technical details
The vulnerability is a stack-based buffer overflow in the firmware update functionality of TL-MR6400 v7, caused by unsafe processing of attacker-controlled metadata within firmware images. An authenticated attacker can craft a malicious firmware image with oversized metadata fields to trigger memory corruption during the update process. Successful exploitation results in arbitrary code execution on the affected device with the privileges of the firmware update process. The attack requires the attacker to have authentication credentials to initiate the firmware update, and a patch has been released (build 260714 as of 2026-08-19) that improves security.
Affected products
- TP-Link TL-MR6400 v7
Timeline
- 2026-08-21: disclosed
- 2026-08-19: patched: Firmware build 260714 (APAC) v7_1.3.0 released with security improvements