CVE-2026-17251
Received Received - Intake

NULL Pointer Dereference in TP-Link TL-MR6400

Vulnerability report for CVE-2026-17251, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: TPLink

Description

A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality ofΒ  TL-MR6400 v7. An unauthenticated remote attacker can trigger the vulnerability by sending a specially crafted HTTP request containing a malformed session cookie header. Successful exploitation may cause the HTTP service process to crash, resulting in a denial-of-service condition and temporary loss of management or CGI functionality until service recovery.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tp-link tl-mr6400 7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a NULL pointer dereference in the HTTP request parsing function of TL-MR6400 v7. An attacker can exploit it by sending a specially crafted HTTP request with a malformed session cookie header. Successful exploitation may crash the HTTP service, causing a denial-of-service and temporary loss of management or CGI functionality until the service recovers.

Detection Guidance

Monitor HTTP service crashes or unresponsiveness on TL-MR6400 devices. Check logs for malformed session cookie headers in HTTP requests. Use network scanning tools to detect unusual traffic patterns targeting the HTTP service.

Impact Analysis

This vulnerability can lead to a denial-of-service condition, disrupting network management and CGI functionality. It may cause temporary loss of access to the device's management interface or web-based controls until the service restarts.

Compliance Impact

This vulnerability causes a denial-of-service condition by crashing the HTTP service, leading to temporary loss of management or CGI functionality. Such disruptions could impact availability requirements under GDPR and HIPAA, which mandate timely access to systems and data. However, the specific compliance impact depends on the system's role in processing personal or health data.

Mitigation Strategies

Apply the latest firmware update from TP-Link if available. Disable remote HTTP management if not required. Use a firewall to block malformed HTTP requests targeting the session cookie header.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17251. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart