Junglewise Threat Intelligence

CVE-2026-17251: TP-Link TL-MR6400 NULL pointer dereference in HTTP parsing

CVE-2026-17251 · Severity: info · CVSS 5.3 · Published 2026-08-21

Technologies: TP-Link TL-MR6400. Vendors: TP-Link.

Executive brief

The TL-MR6400 is a 4G LTE router used by small businesses and remote locations to provide internet connectivity. A flaw in its web administration interface can be triggered remotely without authentication, causing the HTTP service to crash and temporarily disrupting access to the router's management and control functions until it restarts.

Technical details

A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of TL-MR6400 v7. The vulnerability can be triggered by an unauthenticated remote attacker sending a specially crafted HTTP request with a malformed session cookie header. The flaw causes a crash of the HTTP service process, leading to a denial-of-service condition. The vulnerability is network-reachable and requires no prior authentication or user interaction. Exploitation results in temporary unavailability of management and CGI services until the router process recovers.

Affected products

  • TP-Link TL-MR6400 v7

Timeline

  • 2026-08-21: disclosed
  • 2026-08-19: patched: Firmware build 260714 released with security improvements

References

Related threats