CVE-2026-8619 Details
Description
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/archer-mr600/v2/#Firmware | TPLink | Product |
| https://www.tp-link.com/en/support/download/tl-mr100/v3.20/#Firmware | TPLink | Product |
| https://www.tp-link.com/en/support/download/tl-mr150/v3.20/#Firmware | TPLink | Product |
| https://www.tp-link.com/en/support/download/tl-mr6400/v8/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5253/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link tl-mr100 firmware | < 1.3.0 |
CPE
Remediation
| |
| tp-link tl-mr100 | 3.2 |
CPE
Remediation
| |
| tp-link archer mr600 firmware | < 1.10.0 |
CPE
Remediation
| |
| tp-link archer mr600 | 2.0 |
CPE
Remediation
| |
| tp-link tl-mr150 firmware | < 1.3.0 |
CPE
Remediation
| |
| tp-link tl-mr150 | 3.2 |
CPE
Remediation
| |
| tp-link tl-mr6400 firmware | < 1.5.0 |
CPE
Remediation
| |
| tp-link tl-mr6400 | 8.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | Initial Analysis | [email protected] |
| Aug 20, 2026 | CVE Modified | CISA-ADP |
| Aug 20, 2026 | New CVE Received | TPLink |