unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions
that may lead to a NULL pointer dereference.
A remote attacker on an adjacent network can send a specially crated
HTTP request to trigger a crash of the HTTP service process.
Successful
exploitation may cause the HTTP service to crash, making the web management
interface and HTTP-dependent functionality temporarily unavailable.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link archer Mr600 Tp-link archer Mr600 Firmware Tp-link tl-mr100 Tp-link tl-mr100 Firmware Tp-link tl-mr150 Tp-link tl-mr150 Firmware Tp-link tl-mr6400 Tp-link tl-mr6400 Firmware |
|
| CPEs | cpe:2.3:h:tp-link:archer_mr600:2.0:*:*:*:*:*:*:* cpe:2.3:h:tp-link:tl-mr100:3.2:*:*:*:*:*:*:* cpe:2.3:h:tp-link:tl-mr150:3.2:*:*:*:*:*:*:* cpe:2.3:h:tp-link:tl-mr6400:8.0:*:*:*:*:*:*:* cpe:2.3:o:tp-link:archer_mr600_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:tp-link:tl-mr100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:tp-link:tl-mr150_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:tp-link:tl-mr6400_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tp-link
Tp-link archer Mr600 Tp-link archer Mr600 Firmware Tp-link tl-mr100 Tp-link tl-mr100 Firmware Tp-link tl-mr150 Tp-link tl-mr150 Firmware Tp-link tl-mr6400 Tp-link tl-mr6400 Firmware |
|
| Metrics |
cvssV3_1
|
Thu, 20 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable. | |
| Title | Unauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR150, TL-MR6400 and Archer MR600 | |
| Weaknesses | CWE-476 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-08-20T16:27:30.130Z
Reserved: 2026-05-14T18:04:19.124Z
Link: CVE-2026-8619
Updated: 2026-08-20T16:20:41.264Z
Status : Analyzed
Published: 2026-08-20T00:16:53.157
Modified: 2026-09-03T15:04:30.077
Link: CVE-2026-8619
No data.
OpenCVE Enrichment
Updated: 2026-08-20T08:15:17Z