{"id":"CVE-2026-17252","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-17252","summary":"A\nstack-based out-of-bounds write vulnerability exists in the login request\nhandling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated…","details":"A\nstack-based out-of-bounds write vulnerability exists in the login request\nhandling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability\nby sending a specially crafted malformed HTTP request. \n\n\n\n\n\nSuccessful\nexploitation may cause the web service process to crash, resulting in a\ndenial-of-service condition and temporary loss of access to the router's web\nmanagement interface.","published":"2026-08-21T18:16:47.803","modified":"2026-08-21T18:16:47.803","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.tp-link.com/en/support/download/tl-mr6400/v7/#Firmware"},{"type":"WEB","url":"https://www.tp-link.com/tw/support/download/tl-mr6400/v7/#Firmware"},{"type":"WEB","url":"https://www.tp-link.com/us/support/faq/5259/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-21T18:16:47.803"}}