Security Advisory

CVE-2026-17251

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-21 17:16:45
Last updated 2026-08-21 17:40:36
Assigner TPLink
CVSS score 7.1
State PUBLISHED

Description

A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of  TL-MR6400 v7. An unauthenticated remote attacker can trigger the vulnerability by sending a specially crafted HTTP request containing a malformed session cookie header. Successful exploitation may cause the HTTP service process to crash, resulting in a denial-of-service condition and temporary loss of management or CGI functionality until service recovery.