Fiche vulnérabilité
CVE-2026-8619 : faille élevée tp-link tl-mr100 firmware (CVSS 7.5)
Description
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 20 août 2026
- Dernière mise à jour
- 3 sept. 2026
Produits concernés
- tp-link tl-mr100 firmware
- tp-link archer mr600 firmware
- tp-link tl-mr150 firmware
- tp-link tl-mr6400 firmware