Security Advisory

CVE-2026-17252

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-21 17:16:51
Last updated 2026-08-21 17:38:36
Assigner TPLink
CVSS score 7.1
State PUBLISHED

Description

A stack-based out-of-bounds write vulnerability exists in the login request handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability by sending a specially crafted malformed HTTP request. Successful exploitation may cause the web service process to crash, resulting in a denial-of-service condition and temporary loss of access to the router's web management interface.