Junglewise Threat Intelligence

CVE-2026-17252: TP-Link TL-MR6400 v7 stack-based buffer overflow in login handler

CVE-2026-17252 · Severity: info · CVSS 6.5 · Published 2026-08-21

Technologies: TP-Link TL-MR6400. Vendors: TP-Link.

Executive brief

The TP-Link TL-MR6400 v7 is a 4G LTE router used by businesses and consumers to provide wireless internet connectivity. A vulnerability in its web management interface can be exploited by an attacker on the same network to crash the router's web service, temporarily preventing administrators from accessing or managing the device remotely.

Technical details

A stack-based out-of-bounds write vulnerability exists in the login request handling of the TL-MR6400 v7 administrative web interface. An unauthenticated attacker on the adjacent network can send a specially crafted malformed HTTP request to trigger the vulnerability without requiring valid credentials. Successful exploitation causes the web service process to crash, resulting in a denial-of-service condition that temporarily disables web-based management access. A patch was released in firmware version 1.3.0 Build 260714 published on 2026-08-19, which notes "improved security" as a fix.

Affected products

  • TP-Link TL-MR6400 v7 (prior to firmware 1.3.0 Build 260714)

Timeline

  • 2026-08-21: disclosed
  • 2026-08-19: patched: Firmware version 1.3.0 Build 260714 released with security improvements

References

Related threats