Executive brief
TP-Link manufactures a family of 4G/LTE routers widely used in homes and small offices to provide wireless connectivity. A remote attacker on the local network can send a specially crafted HTTP request to crash the router's web management service, temporarily disabling access to the device's configuration interface and any HTTP-dependent functionality. The router must be restarted to restore service.
Technical details
This vulnerability is a NULL pointer dereference in the HTTP service component of TP-Link 4G/LTE routers, caused by improper handling of exceptional or malformed request conditions. The attack vector is network-adjacent (attacker must be on the same local network segment as the target router). No authentication is required; an unauthenticated attacker can send a specially crafted HTTP request to trigger the crash. Successful exploitation causes the HTTP daemon to crash, rendering the web management interface and any HTTP-dependent features temporarily unavailable until the service is manually restarted or the device reboots. Patch availability for these specific firmware versions has not been disclosed in the advisory.
Affected products
- TP-Link TL-MR100 v3.2
- TP-Link TL-MR150 v3.2
- TP-Link TL-MR6400 v8.0
- TP-Link Archer MR600 v2
Timeline
- 2026-08-20: disclosed