CVE-2026-8619
Analyzed Analyzed - Analysis Complete

Denial-of-Service in TP-Link TL-MR100/MR150/MR6400/Archer MR600

Vulnerability report for CVE-2026-8619, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-09-03

Assigner: TPLink

Description

An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference.Β  A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-09-03
Generated
2026-09-09
AI Q&A
2026-08-20
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
tp-link tl-mr100_firmware to 1.3.0 (exc)
tp-link archer_mr600_firmware to 1.10.0 (exc)
tp-link tl-mr150_firmware to 1.3.0 (exc)
tp-link tl-mr6400_firmware to 1.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated denial-of-service vulnerability in TP-Link routers (TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0, Archer MR600 v2). It occurs due to improper handling of HTTP requests, causing a NULL pointer dereference that crashes the HTTP service process. An attacker on the same network can exploit this by sending a specially crafted HTTP request.

Detection Guidance

Detecting this vulnerability requires monitoring for HTTP service crashes on affected TP-Link devices. Check if the web management interface becomes unresponsive or if HTTP-dependent features fail. Use network scanning tools like nmap to identify vulnerable TP-Link models (TL-MR100, TL-MR150, TL-MR6400, Archer MR600) on your network. Monitor logs for HTTP service crashes or NULL pointer dereference errors.

Impact Analysis

Exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent features temporarily unavailable. This could disrupt network management and connectivity until the service restarts or the device is rebooted.

Compliance Impact

This vulnerability causes temporary unavailability of the web management interface and HTTP-dependent features due to an unauthenticated denial-of-service attack. While it does not directly expose data, prolonged unavailability could impact systems relying on HTTP services for critical operations, potentially affecting compliance with standards requiring continuous availability of network services.

Mitigation Strategies

Immediately update the firmware of all affected TP-Link devices to the latest version provided by TP-Link. Download firmware only from the official TP-Link regional website to avoid issues. After updating, verify the HTTP service stability and ensure the web management interface is accessible. Disable unnecessary HTTP services if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8619. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart