TL-MR6400 v7 的固件更新功能中存在一个基于栈的缓冲区溢出漏洞,这是由于对固件映像中由攻击者控制的元数据进行不安全处理所致。 成功利用此漏洞可能允许经过身份验证的攻击者触发内存损坏,并在受影响设备上执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v7.0 | < 1.9.0 Build 260714 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v7.0 | 0 ~ 1.9.0 Build 260714 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-17252 | 7.1 HIGH | Unauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based Out-of-Bounds |
| CVE-2026-17251 | 7.1 HIGH | Unauthenticated Denial of Service via Null Pointer Dereference in HTTP Request Parsing |
No comments yet