CVE-2026-75118
Deferred Deferred - Pending Action

Pre-authentication Stack Buffer Overflow in TP-Link TL-MR100 V3.20

Vulnerability report for CVE-2026-75118, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-01

Assigner: TPLink

Description

A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds checking of encrypted requests to the /cgi/login endpoint. An adjacent unauthenticated attacker with access to the router's web management interface can trigger memory corruption and potentially achieve arbitrary code execution. Successful exploitation can overwrite saved control-flow data on the httpd process stack prior to authentication, resulting in a service crash or potential arbitrary code execution in the context of the affected process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-01
Generated
2026-09-18
AI Q&A
2026-08-29
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tp-link tl-mr100 3.20

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a pre-authentication stack-based buffer overflow in the http_gdpr_decrypt function of TL-MR100 V3.20 routers. It occurs due to insufficient bounds checking of encrypted requests sent to the /cgi/login endpoint. An attacker on the same network can exploit this to corrupt memory and potentially execute arbitrary code before authentication.

Detection Guidance

This vulnerability cannot be directly detected with commands as it requires network-level inspection for unauthorized access attempts to the /cgi/login endpoint. Monitor router logs for unusual requests to /cgi/login and check for crashes in the httpd process. Ensure the router's firmware is updated to the latest version to mitigate the issue.

Impact Analysis

An attacker could crash the router's web management service or take control of the device. This may lead to loss of network connectivity, unauthorized access to the router's settings, or further compromise of connected devices.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data processed by the router, potentially violating GDPR and HIPAA compliance requirements for data protection and confidentiality.

Mitigation Strategies

Immediately update the TL-MR100 router to the latest firmware version to patch the vulnerability. If no update is available, restrict access to the router's web management interface from untrusted networks and disable remote management features.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75118. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart