TP-Link recently patched three high-severity TL-MR6400 router flaws in version 7 hardware. Specifically, these issues allow attackers to run arbitrary code or crash the device. Therefore, users must update their firmware immediately to prevent potential attacks.
- Product: TP-Link Systems Inc. TL-MR6400 v7.0
- Vulnerabilities: 3 flaws (CVE-2026-17250, CVE-2026-17251, CVE-2026-17252)
- Highest severity: 8.5 (High · CVSSv4)
- Worst impact: Authenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update Handling
- Status: No confirmed exploitation yet; patches available
- Action: Update to 1.9.0 Build 260714 now
| CVE | CVSS | Fixed in | Status |
|---|
Why These Vulnerabilities Matter
These vulnerabilities present a severe risk to network security. Furthermore, attackers can gain full control over affected routers. They can also knock the device offline completely. Consequently, this disrupts internet access and potentially compromises connected devices. Fortunately, experts have not confirmed any active exploitation in the wild.
How the Attacks Work
CVE-2026-17250
Looking at the details, CVE-2026-17250 is a stack-based buffer overflow. An authenticated user uploads a firmware image containing malicious metadata. The router mishandles this data, triggering memory corruption and code execution.
CVE-2026-17251
Meanwhile, CVE-2026-17251 involves a null pointer dereference. An unauthenticated attacker sends an HTTP request with a malformed session cookie. As a result, this action crashes the HTTP service instantly.
CVE-2026-17252
Lastly, CVE-2026-17252 is an out-of-bounds write vulnerability. An adjacent attacker sends a malformed HTTP request to the login interface. This crashes the web management service.
Affected Versions and Mitigation Steps
Notably, these issues impact TP-Link TL-MR6400 routers running hardware version 7. The exact number of affected devices currently remains unknown. To resolve this, TP-Link released a fix for these TL-MR6400 router flaws. Users should install firmware version 1.9.0 Build 260714 immediately. Administrators must prioritize this patch to maintain network integrity.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!