在 TP-Link TL-MR100 v3.2、TL-MR150 v3.2、TL-MR6400 v8.0 和 Archer MR600 v2 中发现了一个未认证拒绝服务(DoS)漏洞,原因是未正确处理异常请求条件,可能导致空指针解引用(NULL pointer dereference)。 处于相邻网络的远程攻击者可以发送一个特制的 HTTP 请求,触发 HTTP 服务进程崩溃。 成功利用该漏洞可能导致 HTTP 服务崩溃,从而使基于 Web 的管理界面及依赖于 HTTP 的功能暂时不可用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc | Archer MR600 v2 | < Archer MR600(EU)_V2_1.10.0 Build 260618 |
affected |
| TP-Link Systems Inc. | TL-MR100 v3.2 | < TL-MR100(EU)_V3.20_1.3.0 Build 260609 Rel.49957n |
affected |
| TP-Link Systems Inc. | TL-MR150 v.3.2 | < TL-MR150(EU)_V3.20_1.3.0 Build 260720 Rel.59727n |
affected |
| TP-Link Systems Inc. | TL-MR6400 v8.0 | < TL-MR6400(EN)_V8_1.5.0 Build 260610 Rel.67978n |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | TL-MR100 v3.2 | 0 ~ TL-MR100(EU)_V3.20_1.3.0 Build 260609 Rel.49957n | - |
|
| TP-Link Systems Inc. | TL-MR150 v.3.2 | 0 ~ TL-MR150(EU)_V3.20_1.3.0 Build 260720 Rel.59727n | - |
|
| TP-Link Systems Inc. | TL-MR6400 v8.0 | 0 ~ TL-MR6400(EN)_V8_1.5.0 Build 260610 Rel.67978n | - |
|
| TP-Link Systems Inc | Archer MR600 v2 | 0 ~ Archer MR600(EU)_V2_1.10.0 Build 260618 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75616 | 8.5 HIGH | Command Injection in Router Web Management Interface |
| CVE-2026-75618 | 7.1 HIGH | RTSP Null Pointer Dereference Denial-of-Service Vulnerability on TP-Link Tapo C100 and C10 |
| CVE-2026-75619 | 6.9 MEDIUM | RTSP Heap Buffer Overflow Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101 |
No comments yet