Executive brief
The TL-MR100 is a 4G LTE router used to provide internet connectivity in homes and offices. A pre-authentication buffer overflow vulnerability in its web management interface allows an attacker with local network access to crash the device or potentially execute arbitrary code without logging in, compromising the router's availability and potentially enabling a foothold for further network attacks.
Technical details
A stack-based buffer overflow exists in the http_gdpr_decrypt function within the TL-MR100's httpd process due to insufficient bounds checking when processing encrypted requests to the /cgi/login endpoint. The vulnerability is pre-authentication, requiring only adjacent network access to the router's web management interface; no valid credentials are needed. An attacker can craft malicious encrypted requests that overwrite saved control-flow data on the stack, leading to denial of service (service crash) or arbitrary code execution in the context of the httpd process. TP-Link released firmware version 1.3.0 Build 260609 or later to address this issue.
Affected products
- TP-Link TL-MR100 V3.20 < 1.3.0 Build 260609
Timeline
- 2026-08-28: disclosed