TL-MR6400 v7 的 HTTP 请求解析功能中存在空指针解引用漏洞。未经身份验证的远程攻击者可通过发送包含格式错误的会话 Cookie 头的特制 HTTP 请求来触发该漏洞。 成功利用该漏洞可能导致 HTTP 服务进程崩溃,从而引发拒绝服务(DoS)状况,并在服务恢复前暂时失去管理和 CGI 功能。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v7.0 | < 1.9.0 Build 260714 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v7.0 | 0 ~ 1.9.0 Build 260714 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-17250 | 8.5 HIGH | Authenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update Han |
| CVE-2026-17252 | 7.1 HIGH | Unauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based Out-of-Bounds |
No comments yet