{"id":"CVE-2026-17251","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-17251","summary":"A NULL\npointer dereference vulnerability exists in the HTTP request parsing\nfunctionality of \nTL-MR6400 v7. An unauthenticated remote attacker can\ntrigger the vulnerability by sending…","details":"A NULL\npointer dereference vulnerability exists in the HTTP request parsing\nfunctionality of \nTL-MR6400 v7. An unauthenticated remote attacker can\ntrigger the vulnerability by sending a specially crafted HTTP request\ncontaining a malformed session cookie header. \n\n\n\n\n\nSuccessful\nexploitation may cause the HTTP service process to crash, resulting in a\ndenial-of-service condition and temporary loss of management or CGI\nfunctionality until service recovery.","published":"2026-08-21T18:16:47.660","modified":"2026-08-21T18:16:47.660","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.tp-link.com/en/support/download/tl-mr6400/v7/#Firmware"},{"type":"WEB","url":"https://www.tp-link.com/tw/support/download/tl-mr6400/v7/#Firmware"},{"type":"WEB","url":"https://www.tp-link.com/us/support/faq/5259/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-21T18:16:47.660"}}