Junglewise Threat Intelligence

CVE-2026-8619: TP-Link 4G/LTE router denial of service via malformed HTTP request

CVE-2026-8619 · Severity: high · CVSS 7.5 · Published 2026-08-20

Technologies: TP-Link Archer MR600, TP-Link TL-MR6400. Vendors: TP-Link.

Executive brief

TP-Link manufactures a family of 4G/LTE routers widely used in homes and small offices to provide wireless connectivity. A remote attacker on the local network can send a specially crafted HTTP request to crash the router's web management service, temporarily disabling access to the device's configuration interface and any HTTP-dependent functionality. The router must be restarted to restore service.

Technical details

This vulnerability is a NULL pointer dereference in the HTTP service component of TP-Link 4G/LTE routers, caused by improper handling of exceptional or malformed request conditions. The attack vector is network-adjacent (attacker must be on the same local network segment as the target router). No authentication is required; an unauthenticated attacker can send a specially crafted HTTP request to trigger the crash. Successful exploitation causes the HTTP daemon to crash, rendering the web management interface and any HTTP-dependent features temporarily unavailable until the service is manually restarted or the device reboots. Patch availability for these specific firmware versions has not been disclosed in the advisory.

Affected products

  • TP-Link TL-MR100 v3.2
  • TP-Link TL-MR150 v3.2
  • TP-Link TL-MR6400 v8.0
  • TP-Link Archer MR600 v2

Timeline

  • 2026-08-20: disclosed

References

Related threats