Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-8619— Unauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR150, TL-MR6400 and Archer MR600

Quick assessment

Affected
TP-Link Systems Inc. TL-MR100 v3.2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 TP-Link TL-MR100 v3.2、TL-MR150 v3.2、TL-MR6400 v8.0 和 Archer MR600 v2 中发现了一个未认证拒绝服务(DoS)漏洞,原因是未正确处理异常请求条件,可能导致空指针解引用(NULL pointer dereference)。 处于相邻网络的远程攻击者可以发送一个特制的 HTTP 请求,触发 HTTP 服务进程崩溃。 成功利用该漏洞可能导致 HTTP 服务崩溃,从而使基于 Web 的管理界面及依赖于 HTTP 的功能暂时不可用。

CVSS 7.1 · High EPSS 0.28% · P20

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 4

VendorProduct Version RangeStatus
TP-Link Systems Inc Archer MR600 v2 < Archer MR600(EU)_V2_1.10.0 Build 260618 affected
TP-Link Systems Inc. TL-MR100 v3.2 < TL-MR100(EU)_V3.20_1.3.0 Build 260609 Rel.49957n affected
TP-Link Systems Inc. TL-MR150 v.3.2 < TL-MR150(EU)_V3.20_1.3.0 Build 260720 Rel.59727n affected
TP-Link Systems Inc. TL-MR6400 v8.0 < TL-MR6400(EN)_V8_1.5.0 Build 260610 Rel.67978n affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-8619

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR150, TL-MR6400 and Archer MR600
Source: CVE Program / CVE List V5
Vulnerability Description
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference.  A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
TP-Link Systems Inc. TL-MR100 v3.2 0 ~ TL-MR100(EU)_V3.20_1.3.0 Build 260609 Rel.49957n -
TP-Link Systems Inc. TL-MR150 v.3.2 0 ~ TL-MR150(EU)_V3.20_1.3.0 Build 260720 Rel.59727n -
TP-Link Systems Inc. TL-MR6400 v8.0 0 ~ TL-MR6400(EN)_V8_1.5.0 Build 260610 Rel.67978n -
TP-Link Systems Inc Archer MR600 v2 0 ~ Archer MR600(EU)_V2_1.10.0 Build 260618 -

II. Public POCs for CVE-2026-8619

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-8619

登录查看更多情报信息。

Vendor Advisories for CVE-2026-8619 (1)

Vendor Pages for CVE-2026-8619 (4)

Same Patch Batch · TP-Link Systems Inc. · 2026-08-19 · 4 CVEs total

CVE-2026-75616 8.5 HIGH Command Injection in Router Web Management Interface
CVE-2026-75618 7.1 HIGH RTSP Null Pointer Dereference Denial-of-Service Vulnerability on TP-Link Tapo C100 and C10
CVE-2026-75619 6.9 MEDIUM RTSP Heap Buffer Overflow Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101

IV. Related Vulnerabilities

V. Comments for CVE-2026-8619

No comments yet


Leave a comment