TP-Link TL-MR6400 v7 路由器的管理 Web 界面中的登录请求处理功能存在栈溢出写越界漏洞。未经认证的相邻攻击者可以通过发送特制的畸形 HTTP 请求触发此漏洞。 成功利用该漏洞可能导致 Web 服务进程崩溃,从而造成拒绝服务(DoS)状态,并暂时无法访问路由器的 Web 管理界面。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v7.0 | < 1.9.0 Build 260714 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | TL-MR6400 v7.0 | 0 ~ 1.9.0 Build 260714 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-17250 | 8.5 HIGH | Authenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update Han |
| CVE-2026-17251 | 7.1 HIGH | Unauthenticated Denial of Service via Null Pointer Dereference in HTTP Request Parsing |
No comments yet