CVE-2026-8619
Last modified
CVE-2026-8619 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tl-Mr100 Firmware | < 1.3.0 |
| Tp-Link | Archer Mr600 Firmware | < 1.10.0 |
| Tp-Link | Tl-Mr150 Firmware | < 1.3.0 |
| Tp-Link | Tl-Mr6400 Firmware | < 1.5.0 |
References
- https://www.tp-link.com/us/support/faq/5253/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-8619?
How severe is CVE-2026-8619?
How do I fix CVE-2026-8619?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86184Lara Dashboard before 1.3.0 contains an authentication bypas…9.8
- CVE-2026-86185Bilibili Desktop through 1.18.0 disables TLS certificate ver…8
- CVE-2026-86186AVideo API fails to enforce rate limits when clients send a …6.5
- CVE-2026-86187WWBN AVideo generates passwords for external-login accounts …5.9
- CVE-2026-86188AVideo with YPTSocket plugin enabled contains a cross-site s…7.2
- CVE-2026-86189WWBN AVideo contains a path traversal vulnerability in notif…9.8
- CVE-2026-86190WWBN AVideo contains a broken access control vulnerability i…9.1
- CVE-2026-86191SiYuan versions before v3.8.2 contain an information disclos…4.3
- CVE-2026-86192SiYuan versions before v3.8.2 fail to properly filter privat…6.5
- CVE-2026-86193grav-plugin-api before 1.0.20 fails to validate group-inheri…8.7
- CVE-2026-86194Grav Form Plugin before 9.1.22 fails to verify page authoriz…6.9
- CVE-2026-86195grav-plugin-api versions before 1.0.20 contain a privilege e…8.7
Are you affected by CVE-2026-8619?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
